LayerZero Attributes $290 Million Exploit to Kelp's Security Setup and North Korea's Lazarus Group

LayerZero has attributed the $290 million Kelp DAO exploit to Kelp's own security configuration, specifically the use of a single-verifier setup despite recommendations for a multi-verifier setup. The attackers, preliminarily identified as North Korea's Lazarus Group, compromised two RPC nodes that LayerZero's verifier relied on, allowing them to carry out a fraudulent transaction. The attack was made possible by Kelp's single-verifier setup, which LayerZero had previously warned against. The company has stated that it will no longer sign messages for applications running a 1-of-1 configuration, forcing a protocol-wide migration to multi-verifier setups. The exploit has been linked to North Korea's Lazarus Group, which has been responsible for draining over $575 million from DeFi in 18 days through two separate attacks.