LayerZero Attributes $290 Million Kelp Exploit to Inadequate Security Configuration and North Korean Hackers

LayerZero has identified Kelp's security setup as the primary cause of the $290 million exploit, stating that the protocol's use of a single verifier, despite warnings against this configuration, allowed the attack to occur. The attackers, believed to be affiliated with North Korea's Lazarus Group, compromised two remote procedure call (RPC) nodes and launched a distributed denial-of-service attack on other nodes, resulting in the theft of 116,500 rsETH. LayerZero emphasizes that the attack was only successful due to Kelp's 1-of-1 verifier configuration and notes that its own monitoring infrastructure was not compromised. The company has confirmed that no other applications on the protocol were affected and will no longer support single-verifier setups. The Lazarus Group has been linked to two major DeFi exploits in 18 days, highlighting the need for protocols to enhance their security measures.