LayerZero Points to Kelp's Security Setup as Cause of $290 Million Exploit, Links Attack to North Korea's Lazarus Group
LayerZero has attributed the $290 million Kelp DAO exploit to a security vulnerability in Kelp's setup, stating that the protocol's single-verifier configuration, which the company had warned against, was the primary cause of the attack. The attackers, believed to be affiliated with North Korea's Lazarus Group, compromised two RPC nodes that LayerZero's verifier relied on, and then launched a DDoS attack on the remaining nodes to force a failover to the compromised nodes. This allowed the attackers to manipulate the verifier into releasing 116,500 rsETH. The attack highlights the importance of a multi-verifier setup, which LayerZero had recommended to Kelp, as it would have prevented the exploit by requiring consensus across multiple independent verifiers. The incident has led LayerZero to announce that it will no longer support applications with single-verifier configurations, and the company has confirmed that there has been no contagion to other applications on the protocol.