LayerZero Attributes $290 Million Exploit to Kelp's Security Setup and North Korea's Lazarus Group

LayerZero has attributed the $290 million exploit of Kelp DAO to a security flaw in Kelp's setup, stating that the protocol's single-verifier configuration made it vulnerable to attack. According to LayerZero, the attackers, believed to be from North Korea's Lazarus Group, compromised two RPC nodes and launched a DDoS attack on the remaining nodes, allowing them to trick LayerZero's verifier into confirming a fraudulent transaction. The attack was made possible by Kelp's failure to implement a multi-verifier setup, which LayerZero had recommended. The incident highlights the importance of robust security measures in DeFi protocols and the need for protocols to adapt quickly to evolving attack vectors.