LayerZero Attributes $290 Million Kelp DAO Exploit to Inadequate Security Setup and North Korea's Lazarus Group
LayerZero has attributed the $290 million exploit of Kelp DAO to a security configuration issue, stating that Kelp's use of a single-verifier setup made it vulnerable to attack. The exploit was reportedly carried out by North Korea's Lazarus Group, who compromised two RPC nodes used by LayerZero's verifier and launched a DDoS attack on other nodes to force failover. The attackers then used the compromised nodes to deceive LayerZero's verifier into releasing 116,500 rsETH. LayerZero had previously warned Kelp about the risks of a single-verifier setup and had recommended a multi-verifier configuration. The company has confirmed that there was no contagion to other applications on the protocol and has announced that it will no longer support single-verifier setups. The exploit has raised concerns about the security of DeFi protocols and the ability of attackers to adapt and evolve their tactics.