LayerZero Attributes $290 Million Kelp Exploit to Inadequate Security Setup, Links to North Korea's Lazarus Group

LayerZero has identified Kelp's security configuration as the primary cause of the $290 million exploit, citing the protocol's use of a single-verifier setup despite warnings against such a configuration. The attack, attributed with preliminary confidence to North Korea's Lazarus Group, involved the compromise of two RPC nodes that LayerZero's verifier relied on, which were then used to deceive the verifier into confirming a fraudulent transaction. The attackers also launched a distributed denial-of-service attack on uncompromised RPC nodes to force failover to the compromised ones. The attack's success was contingent upon Kelp's single-verifier setup, as a multi-verifier configuration would have required consensus across several independent verifiers to confirm a message, thereby preventing the forgery of a valid message. LayerZero has confirmed that there was no contagion to other applications on the protocol and has taken steps to prevent similar attacks in the future, including refusing to sign messages for applications with single-verifier setups.