LayerZero Attributes $290 Million Kelp DAO Exploit to Inadequate Security Setup and North Korean Hackers

LayerZero has attributed the $290 million Kelp DAO exploit to Kelp's own security configuration, specifically the use of a single-verifier setup despite previous warnings. The attackers, believed to be North Korea's Lazarus Group, compromised two RPC nodes and launched a DDoS attack on others, allowing them to forge a valid cross-chain transaction. This attack vector targeted the infrastructure layer rather than protocol code, and its success was facilitated by Kelp's failure to implement a multi-verifier setup with redundancy. The incident highlights the importance of robust security configurations and the need for DeFi protocols to harden their defenses against increasingly sophisticated attacks. LayerZero has confirmed no contagion to other applications and will no longer support single-verifier setups, emphasizing the need for a protocol-wide migration to more secure configurations.