LayerZero Attributes $290 Million Exploit to Kelp's Security Setup and North Korea's Lazarus Group
LayerZero has attributed the $290 million Kelp DAO exploit to Kelp's own security configuration, stating that the protocol's single-verifier setup, which was warned against, allowed the attack to occur. The attackers, believed to be North Korea's Lazarus Group, compromised two RPC nodes that LayerZero's verifier relied on, and then launched a DDoS attack on other nodes to force a failover. This selective attack allowed the attackers to deceive LayerZero's verifier into releasing 116,500 rsETH. The attack's success was solely due to Kelp's 1-of-1 verifier configuration, which LayerZero had recommended against in favor of a multi-verifier setup with redundancy. LayerZero has confirmed no contagion to other applications on the protocol and has since come back online, stating it will no longer support single-verifier configurations.