LayerZero Attributes $290 Million Kelp DAO Exploit to North Korea's Lazarus, Citing Security Setup
LayerZero has identified the root cause of the $290 million Kelp DAO exploit as Kelp's own security configuration, specifically the use of a single-verifier setup, which the company had previously advised against. The attack, attributed to North Korea's Lazarus Group, involved the compromise of two RPC nodes that LayerZero's verifier relied on, allowing the attackers to manipulate data and execute a fraudulent transaction. The attackers then conducted a DDoS attack on other RPC nodes, forcing a failover to the compromised nodes and resulting in the release of 116,500 rsETH to the attackers. LayerZero emphasized that the attack was only successful due to Kelp's single-verifier configuration and noted that a multi-verifier setup would have prevented the exploit. The company has confirmed that there was no contagion to other applications on the protocol and has taken steps to prevent similar attacks in the future, including refusing to sign messages for applications with single-verifier setups.