LayerZero Attributes $290 Million Kelp Exploit to Inadequate Security Setup and North Korea's Lazarus Group

LayerZero has attributed the $290 million exploit of Kelp DAO to the protocol's own security configuration, stating that Kelp's use of a single-verifier setup, despite recommendations for a multi-verifier configuration, made the attack possible. The attackers, believed to be affiliated with North Korea's Lazarus Group, compromised two RPC nodes that LayerZero's verifier relied on, using them to validate a fraudulent transaction while maintaining accurate data for other systems. The attack was only successful due to Kelp's single-verifier setup, as a multi-verifier configuration would have required consensus across multiple independent verifiers to confirm a message. LayerZero has confirmed that no other applications on the protocol were affected and has since taken steps to prevent similar attacks in the future, including refusing to sign messages for applications with single-verifier setups. This incident highlights the importance of robust security configurations and the need for DeFi protocols to adapt quickly to evolving threats.