LayerZero Attributes $290 Million Kelp DAO Exploit to North Korea's Lazarus, Citing Security Setup
LayerZero has attributed the $290 million exploit of Kelp DAO to the protocol's single-verifier setup, which the company had warned against. The attack, which LayerZero believes was carried out by North Korea's Lazarus Group, involved compromising two remote procedure call (RPC) nodes and using them to feed false information to LayerZero's verifier. The verifier, which relied on these nodes for cross-chain transactions, was tricked into releasing 116,500 rsETH to the attackers. LayerZero's monitoring infrastructure was unable to detect the attack due to the selective nature of the compromised nodes' reporting. The attack was only possible because Kelp had ignored recommendations to implement a multi-verifier setup, which would have required consensus across several independent verifiers to confirm a message. LayerZero has confirmed that no other applications on the protocol were affected and has announced that it will no longer support single-verifier setups. The company's verifier is back online, and a protocol-wide migration to multi-verifier setups is underway. The attack highlights the importance of robust security configurations and the need for DeFi protocols to adapt quickly to evolving threats.