LayerZero Attributes $290 Million Kelp DAO Exploit to Inadequate Security Setup and North Korea's Lazarus Group

LayerZero has assigned blame for the $290 million Kelp DAO exploit to Kelp's own security configuration, citing the protocol's use of a single-verifier setup despite previous warnings against such a configuration. The attackers, preliminarily identified as North Korea's Lazarus Group, compromised two RPC nodes that LayerZero's verifier relied on, manipulating them to validate a fraudulent transaction while appearing legitimate to other systems. This was made possible by Kelp's failure to implement a multi-verifier setup with redundancy, which would have required consensus across several independent verifiers to confirm a message. LayerZero's verifier has been restored, and the company will no longer support applications with single-verifier configurations, prompting a protocol-wide shift away from such setups. The exploit's success, attributed to Kelp's security choices rather than a protocol-level bug, has significant implications for how DeFi assesses LayerZero's risk. Meanwhile, the Lazarus Group's involvement marks its second major exploit in 18 days, following the Drift Protocol attack, totaling over $575 million drained from DeFi through distinct attack vectors.