LayerZero Points to Kelp's Security Setup as Cause of $290 Million Exploit, Links Attack to North Korea's Lazarus Group
LayerZero has attributed the $290 million Kelp DAO exploit to Kelp's own security configuration, stating that the protocol's single-verifier setup, despite recommendations for a multi-verifier setup, was the vulnerability that led to the attack. The attackers, believed to be associated with North Korea's Lazarus Group, compromised two RPC nodes that LayerZero's verifier relied on, and then conducted a DDoS attack on other nodes to force a failover to the compromised ones. This sophisticated attack was only possible due to Kelp's single-verifier configuration, which LayerZero had warned against. The company has confirmed that there was no contagion to other applications on the protocol and has since taken measures to prevent such attacks in the future, including refusing to sign messages for applications with single-verifier setups. The exploit highlights the importance of robust security configurations and the evolving threats posed by groups like Lazarus, which has been linked to over $575 million in DeFi losses in recent weeks.