LayerZero Attributes $290 Million Exploit to Kelp's Security Setup and North Korea's Lazarus Group

LayerZero has attributed the $290 million Kelp DAO exploit to Kelp's own security configuration, stating that the protocol's single-verifier setup, which LayerZero had warned against, was the primary cause of the vulnerability. The attackers, believed to be associated with North Korea's Lazarus Group and its TraderTraitor subunit, compromised two RPC nodes that LayerZero's verifier relied on, allowing them to manipulate the system into releasing 116,500 rsETH. The attack was made possible by Kelp's failure to implement a multi-verifier setup, which would have required consensus across several independent verifiers to confirm a message. LayerZero's verifier has been restored, and the company will no longer support applications with single-verifier configurations, prompting a protocol-wide migration to more secure setups. The exploit has been linked to the Lazarus Group, which has been responsible for over $575 million in DeFi losses in the past 18 days, highlighting the group's rapid adaptation of its attack strategies.