LayerZero Attributes $290 Million Exploit to Kelp's Configuration and North Korea's Lazarus Group
LayerZero has stated that the $290 million exploit of Kelp DAO is a result of Kelp's security setup, specifically the use of a single-verifier configuration despite recommendations for a multi-verifier setup. The attack, which LayerZero attributes with preliminary confidence to North Korea's Lazarus Group, involved compromising two remote procedure call (RPC) nodes that LayerZero's verifier relied on, and then conducting a distributed denial-of-service (DDoS) attack on other nodes to force failover to the compromised ones. This allowed the attackers to fraudulently release 116,500 rsETH. The attack's success is attributed to Kelp's decision to ignore recommendations for a multi-verifier setup, which would have required consensus across several independent verifiers to confirm a message, thereby preventing the attack. LayerZero has confirmed that there is no contagion to other applications on the protocol and has taken steps to prevent similar attacks in the future, including requiring a protocol-wide migration off single-verifier setups.