LayerZero Attributes $290 Million Kelp Exploit to North Korea's Lazarus, Citing Kelp's Security Setup

LayerZero has attributed the $290 million Kelp DAO exploit to Kelp's own security configuration, specifically the use of a single-verifier setup despite recommendations for a multi-verifier setup. The attack, which LayerZero believes with preliminary confidence was carried out by North Korea's Lazarus Group, involved compromising two remote procedure call (RPC) nodes that LayerZero's verifier relied on, and then conducting a distributed denial-of-service (DDoS) attack on other RPC nodes to force a failover to the compromised nodes. The attackers then used the compromised nodes to deceive LayerZero's verifier into releasing 116,500 rsETH. LayerZero emphasizes that the attack was only possible due to Kelp's single-verifier setup and notes that its own protocol worked as designed, with the issue lying in Kelp's security choices. The company has confirmed no contagion to other applications on the protocol and will no longer support single-verifier configurations, pushing for a protocol-wide migration to multi-verifier setups. This incident marks the second major exploit attributed to Lazarus Group in less than a month, following the Drift Protocol exploit on April 1, and highlights the group's rapid adaptation of its attack strategies.