LayerZero Points to Kelp's Security Setup as Cause of $290 Million Exploit, Links Attack to North Korea's Lazarus Group
LayerZero has attributed the $290 million Kelp DAO exploit to Kelp's security configuration, specifically the use of a single-verifier setup despite recommendations for a multi-verifier configuration. The attack, which LayerZero links to North Korea's Lazarus Group with preliminary confidence, involved compromising two RPC nodes that LayerZero's verifier relied on, and then launching a DDoS attack on other nodes to force a failover to the compromised ones. This allowed the attackers to trick LayerZero's verifier into releasing 116,500 rsETH. The attack's success is attributed to Kelp's single-verifier setup, which LayerZero had warned against. The company has confirmed that there was no contagion to other applications on the protocol and has since brought its verifier back online, announcing it will no longer support single-verifier configurations.