LayerZero Attributes $290 Million Kelp Exploit to North Korea's Lazarus Group, Citing Kelp's Security Setup
LayerZero has attributed the $290 million exploit of Kelp DAO to the protocol's single-verifier setup, which the company had previously advised against. According to LayerZero, the attackers, believed to be North Korea's Lazarus Group, compromised two remote procedure call (RPC) nodes that the verifier relied on, and then launched a distributed denial-of-service (DDoS) attack on other nodes to force a failover. The attack was only successful due to Kelp's 1-of-1 verifier configuration, which LayerZero had recommended against. The company has confirmed that no other applications on the protocol were affected and has announced that it will no longer support single-verifier setups. The exploit has been linked to the Lazarus Group, which has been responsible for over $575 million in DeFi losses in the past 18 days.