LayerZero Attributes $290 Million Kelp Exploit to Inadequate Security Setup and North Korea's Lazarus Group

LayerZero has attributed the $290 million Kelp DAO exploit to Kelp's security configuration, stating that the protocol's single-verifier setup, which the company had warned against, was the primary cause of the breach. The attackers, believed to be linked to North Korea's Lazarus Group, compromised two remote procedure call (RPC) nodes that LayerZero's verifier relied on, allowing them to manipulate cross-chain transactions. This was made possible by Kelp's failure to implement a multi-verifier setup, which would have required consensus across multiple independent verifiers to confirm a message. As a result, LayerZero will no longer support applications with single-verifier configurations, effectively forcing a protocol-wide migration to more secure setups. The company has confirmed that the attack did not affect any other applications on the protocol, and the LayerZero Labs verifier is now back online.