LayerZero Pins $290 Million Exploit on Kelp's Security Setup, Links Attack to North Korea's Lazarus Group

LayerZero has attributed the $290 million exploit of Kelp DAO to the protocol's own security configuration, stating that Kelp's use of a single-verifier setup made it vulnerable to attack. The attackers, believed to be North Korea's Lazarus Group, compromised two RPC nodes that LayerZero's verifier relied on, and then launched a DDoS attack on other nodes to force a failover to the compromised ones. This allowed the attackers to fraudulently release 116,500 rsETH. LayerZero had previously warned Kelp against using a single-verifier setup, recommending a multi-verifier configuration for added security. The company has confirmed that no other applications on the protocol were affected and has announced that it will no longer support single-verifier setups. The attack highlights the importance of robust security measures in DeFi protocols and the need for vigilance against evolving attack vectors.