LayerZero Attributes $290 Million Exploit to Kelp's Security Setup, Links Attack to North Korea's Lazarus Group

LayerZero has attributed the $290 million Kelp DAO exploit to Kelp's own security configuration, stating that the protocol's single-verifier setup, which LayerZero had warned against, allowed the attack to occur. The attackers, who LayerZero believes with preliminary confidence to be North Korea's Lazarus Group, compromised two RPC nodes that LayerZero's verifier relied on, then launched a DDoS attack on other nodes to force failover to the compromised ones. This allowed the attackers to trick LayerZero's verifier into releasing 116,500 rsETH. The attack was only possible due to Kelp's 1-of-1 verifier configuration, which LayerZero had recommended against in favor of a multi-verifier setup. LayerZero has confirmed that no other applications on the protocol were affected and has since brought its verifier back online, announcing that it will no longer support single-verifier configurations.