LayerZero Attributes $290 Million Kelp Exploit to North Korea's Lazarus, Citing Security Setup
LayerZero has attributed the $290 million Kelp DAO exploit to Kelp's security configuration, stating that the protocol's single-verifier setup, despite previous warnings, enabled the attack. The attackers, believed to be North Korea's Lazarus Group, compromised two RPC nodes and launched a DDoS attack on other nodes, resulting in the release of 116,500 rsETH. LayerZero's verifier relied on these nodes to confirm cross-chain transactions, and the attackers manipulated the nodes to report false data. The attack was only successful due to Kelp's 1-of-1 verifier configuration, which LayerZero had recommended against. The company has confirmed no contagion to other applications and will no longer support single-verifier setups. This incident highlights the importance of multi-verifier configurations and the need for DeFi protocols to enhance their security measures against evolving threats.