LayerZero Attributes $290 Million Exploit to Kelp's Security Setup and North Korea's Lazarus Group
LayerZero has attributed the $290 million Kelp DAO exploit to a security configuration flaw on Kelp's part, stating that the protocol's single-verifier setup made it vulnerable to attack. The attackers, believed to be North Korea's Lazarus Group, compromised two RPC nodes and launched a DDoS attack on other nodes to force a failover, allowing them to steal 116,500 rsETH. LayerZero had previously warned Kelp against using a single-verifier setup, recommending a multi-verifier configuration for added security. The attack highlights the importance of robust security measures in DeFi protocols and the need for protocols to adapt quickly to evolving threats.