LayerZero Attributes $290 Million Kelp Exploit to Inadequate Security Setup, Points to North Korea's Lazarus Group
LayerZero has asserted that the $290 million exploit of Kelp DAO was a direct result of Kelp's security setup, specifically the use of a single-verifier configuration, which the company had warned against. The attack, attributed to North Korea's Lazarus Group, involved the compromise of two remote procedure call (RPC) nodes that LayerZero's verifier relied on, allowing the attackers to manipulate transaction data. This was combined with a distributed denial-of-service (DDoS) attack on uncompromised external RPC nodes to force a failover to the compromised nodes. The attack's success was contingent upon Kelp's single-verifier setup, as a multi-verifier configuration would have required consensus across several independent verifiers to confirm a message, thereby preventing the attack. LayerZero has confirmed that there was no contagion to other applications on the protocol and has since taken steps to prevent similar attacks, including refusing to sign messages for applications with single-verifier setups.