LayerZero Attributes $290 Million Kelp Exploit to Inadequate Security Setup and North Korea's Lazarus Group

LayerZero has attributed the $290 million Kelp DAO exploit to Kelp's security configuration, stating that the protocol's single-verifier setup, despite previous warnings, allowed the attack to occur. The attackers, believed to be from North Korea's Lazarus Group, compromised two RPC nodes that LayerZero's verifier relied on, manipulating them to validate a fraudulent transaction while providing accurate data to other systems. This was made possible by Kelp's failure to implement a multi-verifier setup, which would have required consensus across several independent verifiers to confirm a message. LayerZero's verifier was deceived into releasing 116,500 rsETH to the attackers after the compromised nodes reported a valid cross-chain message. The attack was facilitated by a distributed denial-of-service attack on uncompromised external RPC nodes, forcing a failover to the poisoned ones. LayerZero emphasized that the attack would not have been successful if Kelp had followed recommendations for a multi-verifier setup, highlighting the importance of security configurations in preventing such exploits. The incident underscores the evolving threat landscape in DeFi, with Lazarus Group linked to over $575 million in losses from two exploits in 18 days.