LayerZero Attributes $290 Million Kelp DAO Exploit to North Korea's Lazarus, Citing Kelp's Security Setup

LayerZero has attributed the $290 million exploit of Kelp DAO to a security configuration issue on Kelp's part, stating that the protocol's single-verifier setup, which it had warned against, was the primary cause of the breach. The attackers, believed to be North Korea's Lazarus Group, compromised two RPC nodes that LayerZero's verifier relied on, then launched a distributed denial-of-service attack on the remaining nodes to force a failover to the compromised ones. This allowed them to trick LayerZero's verifier into releasing 116,500 rsETH to the attackers. The attack was made possible by Kelp's decision to run a 1-of-1 verifier configuration, despite LayerZero's recommendations for a multi-verifier setup with redundancy. LayerZero has confirmed that no other applications on the protocol were affected and has since taken steps to prevent similar attacks in the future, including refusing to sign messages for applications with single-verifier setups.