LayerZero Attributes $290 Million Exploit to Kelp's Security Setup and North Korea's Lazarus Group

LayerZero has attributed the $290 million Kelp DAO exploit to Kelp's own security configuration, stating that the protocol's single-verifier setup, which LayerZero had previously advised against, was the primary factor in the attack. The exploit was reportedly carried out by North Korea's Lazarus Group and its TraderTraitor subunit. According to LayerZero, the attackers compromised two remote procedure call (RPC) nodes that the company's verifier relied on to confirm cross-chain transactions, and then launched a distributed denial-of-service attack on other external RPC nodes to force a failover to the compromised nodes. This allowed the attackers to trick LayerZero's verifier into releasing 116,500 rsETH. LayerZero emphasized that the attack would not have been successful if Kelp had implemented a multi-verifier setup with redundancy, as recommended by the company. The incident has been contained, with no contagion to other applications on the protocol, and LayerZero will no longer support single-verifier configurations.