LayerZero Attributes $290 Million Kelp DAO Exploit to Inadequate Security Setup and North Korea's Lazarus Group

LayerZero has attributed the $290 million exploit of Kelp DAO to the protocol's single-verifier configuration, which the company had warned against. The attackers, believed to be North Korea's Lazarus Group, compromised two RPC nodes and launched a DDoS attack on others, allowing them to forge a fraudulent transaction. This attack vector targeted the infrastructure layer rather than protocol code. The attackers manipulated the nodes to deceive LayerZero's verifier, making it appear as though a valid cross-chain transaction had occurred. LayerZero's own monitoring infrastructure was unable to detect the attack due to the selective manipulation of the nodes. The company had recommended a multi-verifier setup to Kelp, which would have required consensus across several independent verifiers to confirm a message, thereby preventing the attack. LayerZero has confirmed that no other applications on the protocol were affected and has since taken steps to prevent similar attacks in the future, including refusing to sign messages for applications with single-verifier configurations. The exploit highlights the importance of proper security configurations and the evolving nature of attacks on DeFi protocols.