LayerZero Attributes $290 Million Exploit to Kelp's Security Setup and North Korea's Lazarus Group

LayerZero has attributed the $290 million Kelp DAO exploit to Kelp's own security configuration, stating that the protocol's single-verifier setup, which LayerZero had previously advised against, made the attack possible. The attackers, believed to be North Korea's Lazarus Group, compromised two RPC nodes that LayerZero's verifier relied on, and then launched a DDoS attack on other nodes to force a failover to the compromised ones. This allowed the attackers to release 116,500 rsETH. LayerZero emphasizes that the attack would not have been possible if Kelp had implemented a multi-verifier setup with redundancy, as recommended. The company has confirmed that there was no contagion to other applications on the protocol and has since taken the LayerZero Labs verifier offline for applications with single-verifier configurations, prompting a protocol-wide migration to multi-verifier setups.