LayerZero Attributes $290 Million Kelp DAO Exploit to North Korea's Lazarus Group, Citing Kelp's Security Setup
LayerZero has pinned the blame for the $290 million Kelp DAO exploit on Kelp's security configuration, specifically the use of a single-verifier setup despite previous warnings against it. The attack, attributed to North Korea's Lazarus Group, exploited a novel vector targeting the infrastructure layer. Attackers compromised two RPC nodes, swapping their software with malicious versions to deceive LayerZero's verifier into confirming a fraudulent transaction. A DDoS attack was also launched on uncompromised nodes to force failover to the compromised ones. LayerZero emphasizes that the attack was only possible due to Kelp's 1-of-1 verifier configuration and notes that a multi-verifier setup would have prevented the exploit. The company has confirmed no contagion to other applications and will no longer support single-verifier configurations.