LayerZero Attributes $290 Million Kelp Exploit to Security Setup and North Korea's Lazarus Group
LayerZero has attributed the $290 million exploit of Kelp DAO to the protocol's security configuration, stating that Kelp's use of a single-verifier setup made it vulnerable to attack. The exploit was carried out by compromising two remote procedure call (RPC) nodes that LayerZero's verifier relied on, and then conducting a distributed denial-of-service attack on other nodes to force failover to the compromised ones. LayerZero had previously recommended a multi-verifier setup to Kelp, which would have required consensus across several independent verifiers to confirm a message, making the attack more difficult to execute. The attack has been attributed to North Korea's Lazarus Group, which has been linked to another recent DeFi exploit, and highlights the need for DeFi protocols to strengthen their security measures.