LayerZero Attributes $290 Million Exploit to Kelp's Security Setup and North Korea's Lazarus Group

LayerZero has shifted the blame for the $290 million Kelp DAO exploit to Kelp's own security configuration, stating that the protocol's single-verifier setup, which LayerZero had warned against, was the primary cause of the vulnerability. The attack, attributed to North Korea's Lazarus Group with preliminary confidence, exploited a novel vector targeting the infrastructure layer. The attackers compromised two RPC nodes that LayerZero's verifier relied on, then launched a DDoS attack on other nodes to force a failover to the compromised ones. This selective attack allowed the perpetrators to remain undetected by LayerZero's monitoring infrastructure. The attack's success was contingent upon Kelp's 1-of-1 verifier configuration, which LayerZero had recommended against in favor of a multi-verifier setup. LayerZero has confirmed that the attack did not affect any other applications on the protocol and has since taken steps to prevent similar incidents, including refusing to sign messages for applications with single-verifier configurations.