LayerZero Attributes $290 Million Exploit to Kelp's Security Setup and North Korea's Lazarus Group
LayerZero has attributed the $290 million Kelp DAO exploit to Kelp's own security configuration, stating that the protocol's single-verifier setup, which was previously warned against, made it vulnerable to attack. The attackers, believed to be North Korea's Lazarus Group, compromised two remote procedure call (RPC) nodes that LayerZero's verifier relied on, and then launched a distributed denial-of-service attack on other nodes to force failover to the compromised ones. This allowed the attackers to steal 116,500 rsETH. LayerZero had recommended a multi-verifier setup, which would have required consensus across several independent verifiers to confirm a message, making the attack more difficult. The company has confirmed that there was no contagion to other applications on the protocol and has since taken the LayerZero Labs verifier offline for applications with single-verifier setups. This incident highlights the importance of security configurations and the need for DeFi protocols to harden their defenses against evolving attack vectors.