LayerZero Attributes $290 Million Kelp Exploit to Inadequate Security Setup and North Korean Hackers

LayerZero has attributed the $290 million exploit of Kelp DAO to the protocol's single-verifier setup, which it had previously advised against. According to LayerZero, the attackers, believed to be North Korea's Lazarus Group and its TraderTraitor subunit, compromised two RPC nodes that LayerZero's verifier relied on, allowing them to manipulate transactions. The attack was made possible by Kelp's failure to implement a multi-verifier setup, which would have required consensus across several independent verifiers to confirm a message. LayerZero has confirmed that there was no contagion to other applications on the protocol and has taken steps to prevent similar attacks in the future, including refusing to sign messages for applications with single-verifier setups. The attack highlights the importance of robust security configurations and the need for DeFi protocols to harden their defenses against increasingly sophisticated threats.