LayerZero Pins $290 Million Exploit on Kelp's Security Setup, Links Attack to North Korea's Lazarus Group
LayerZero has attributed the $290 million exploit of Kelp DAO to a security configuration issue, stating that Kelp's use of a single-verifier setup made it vulnerable to the attack. The attackers, believed to be North Korea's Lazarus Group, compromised two remote procedure call (RPC) nodes and launched a distributed denial-of-service (DDoS) attack on other nodes to force a failover. This allowed them to trick LayerZero's verifier into releasing 116,500 rsETH to the attackers. The attack was only successful due to Kelp's non-compliance with LayerZero's recommendation for a multi-verifier setup. LayerZero has confirmed that the attack did not affect any other applications on the protocol and has since taken steps to prevent similar incidents, including refusing to sign messages for applications with single-verifier configurations. The exploit has raised concerns about the security of DeFi protocols and the adaptability of attackers like the Lazarus Group.