LayerZero Attributes $290 Million Exploit to Kelp's Security Setup and North Korea's Lazarus Group
LayerZero has pinpointed Kelp's security configuration as the primary cause of the $290 million exploit, stating that the protocol's single-verifier setup, which was previously warned against, allowed the attack to occur. The attackers, believed to be affiliated with North Korea's Lazarus Group, compromised two RPC nodes that LayerZero's verifier relied on, and then launched a DDoS attack on other nodes to force a failover to the compromised ones. This resulted in the release of 116,500 rsETH to the attackers. The attack was only successful due to Kelp's 1-of-1 verifier configuration, which LayerZero had recommended against in favor of a multi-verifier setup. LayerZero has confirmed that there was no contagion to other applications on the protocol and has since brought its verifier back online, but will no longer sign messages for applications using a single-verifier setup.