LayerZero Attributes $290 Million Kelp DAO Exploit to Inadequate Security Setup, Links Attack to North Korea's Lazarus Group

LayerZero has attributed the $290 million exploit of Kelp DAO to the protocol's single-verifier security configuration, which the company had warned against. According to LayerZero, the attackers, believed to be associated with North Korea's Lazarus Group, compromised two remote procedure call (RPC) nodes that the verifier relied on, and launched a distributed denial-of-service (DDoS) attack on other nodes to force a failover to the compromised ones. The attack was only successful due to Kelp's use of a 1-of-1 verifier configuration, which allowed the attackers to forge a valid message by manipulating the compromised nodes. LayerZero had recommended a multi-verifier setup with redundancy, which would have prevented the attack. The company has confirmed that there was no contagion to other applications on the protocol and has taken steps to prevent similar attacks in the future, including refusing to sign messages for applications with single-verifier setups. The exploit has been linked to North Korea's Lazarus Group, which has been responsible for over $575 million in DeFi losses in the past 18 days through two separate attacks.