LayerZero Attributes $290 Million Exploit to Kelp's Security Setup and North Korea's Lazarus Group
LayerZero has attributed the $290 million exploit of Kelp DAO to a security configuration issue on Kelp's part, stating that the protocol's single-verifier setup, which LayerZero had warned against, was the primary factor in the attack. The attackers, preliminarily identified as North Korea's Lazarus Group, compromised two RPC nodes used by LayerZero's verifier, allowing them to manipulate transaction data and ultimately steal 116,500 rsETH. The attack was only successful due to Kelp's use of a single verifier, as a multi-verifier setup would have required consensus across multiple independent verifiers to confirm a message. LayerZero has confirmed that there was no contagion to other applications on the protocol and has since taken steps to prevent similar attacks in the future, including refusing to sign messages for applications with single-verifier setups.