LayerZero Attributes $290 Million Exploit to Kelp's Security Setup and North Korea's Lazarus Group
LayerZero has attributed the $290 million Kelp DAO exploit to Kelp's own security configuration, stating that the protocol's single-verifier setup, which was previously warned against, allowed the attack to occur. The attack, which was attributed with preliminary confidence to North Korea's Lazarus Group and its TraderTraitor subunit, involved compromising two remote procedure call (RPC) nodes that LayerZero's verifier relied on, and then conducting a distributed denial-of-service (DDoS) attack on other RPC nodes. This led to the release of 116,500 rsETH to the attackers. LayerZero emphasized that the attack would not have been possible if Kelp had implemented a multi-verifier setup, which would have required consensus across several independent verifiers to confirm a message. The company has confirmed that there was no contagion to other applications on the protocol and has since taken the LayerZero Labs verifier offline, stating that it will no longer sign messages for applications running a 1-of-1 configuration.