LayerZero Attributes $290 Million Kelp Exploit to Poor Security Setup and North Korean Hackers
LayerZero has attributed the $290 million exploit of Kelp DAO to a security configuration issue, stating that Kelp's use of a single-verifier setup made it vulnerable to attack. The attackers, believed to be North Korea's Lazarus Group, compromised two RPC nodes and launched a DDoS attack on other nodes to force a failover, resulting in the theft of 116,500 rsETH. LayerZero had previously warned Kelp about the risks of a single-verifier setup and recommended a multi-verifier configuration. The attack has been linked to North Korea's Lazarus Group, which has been responsible for over $575 million in DeFi exploits in the past 18 days.