LayerZero Points to Kelp's Security Setup as Cause of $290 Million Exploit, Links Attack to North Korea's Lazarus Group

LayerZero attributes the $290 million exploit of Kelp DAO to Kelp's own security configuration, specifically the use of a single-verifier setup despite previous warnings against it. The attack, preliminarily linked to North Korea's Lazarus Group, involved compromising two RPC nodes that LayerZero's verifier relied on, and then launching a DDoS attack on other nodes to force a failover. This allowed the attackers to forge a valid cross-chain message, resulting in the release of 116,500 rsETH. LayerZero emphasizes that the attack was only possible due to Kelp's 1-of-1 verifier configuration and notes that its public integration checklist and direct communications had recommended a multi-verifier setup with redundancy. The company confirms that there was no contagion to other applications on the protocol and that the LayerZero Labs verifier is back online, with plans to no longer support single-verifier setups.