LayerZero Attributes $290 Million Exploit to Kelp's Security Setup and North Korea's Lazarus Group

LayerZero has attributed the $290 million Kelp DAO exploit to Kelp's own security configuration, specifically the use of a single-verifier setup that the company had warned against. The attack, which LayerZero believes with preliminary confidence was carried out by North Korea's Lazarus Group and its TraderTraitor subunit, involved compromising two remote procedure call (RPC) nodes used by LayerZero's verifier to confirm cross-chain transactions. The attackers then used these compromised nodes to deceive LayerZero's verifier into releasing 116,500 rsETH, while also launching a distributed denial-of-service attack on other external RPC nodes to force a failover to the compromised ones. The attack highlights the importance of a multi-verifier setup with redundancy, as recommended by LayerZero, which would have prevented the exploit by requiring consensus across several independent verifiers to confirm a message. LayerZero has confirmed that there was no contagion to other applications on the protocol and has since brought its verifier back online, announcing that it will no longer support applications with single-verifier setups.