LayerZero Attributes $290 Million Kelp Exploit to Inadequate Security Configuration and North Korea's Lazarus Group

LayerZero has attributed the $290 million Kelp DAO exploit to Kelp's own security setup, stating that the protocol's single-verifier configuration, contrary to their recommendations, allowed the attack to succeed. The attack, attributed with preliminary confidence to North Korea's Lazarus Group, involved compromising two RPC nodes that LayerZero's verifier relied on, and then conducting a DDoS attack on other nodes to force a failover. This selective manipulation of data allowed the attackers to deceive LayerZero's verifier into releasing 116,500 rsETH. The attack's success was facilitated by Kelp's failure to implement a multi-verifier setup, which would have required consensus across several independent verifiers to confirm a message. LayerZero had explicitly recommended this setup to Kelp to enhance security. The company has confirmed that there was no contagion to other applications on the protocol and has since taken the LayerZero Labs verifier offline, announcing that it will no longer support applications with single-verifier configurations. This incident highlights the importance of robust security configurations in DeFi protocols and the evolving threats posed by sophisticated actors like the Lazarus Group.