LayerZero Attributes $290 Million Kelp Exploit to Inadequate Security Setup and North Korea's Lazarus Group

LayerZero has attributed the $290 million Kelp DAO exploit to Kelp's own security configuration, specifically a single-verifier setup that the company had warned against. The attackers, believed to be North Korea's Lazarus Group, compromised two remote procedure call (RPC) nodes and launched a distributed denial-of-service attack on other nodes to force a failover, ultimately leading to the release of 116,500 rsETH to the attackers. This attack vector targeted the infrastructure layer, exploiting Kelp's failure to implement a multi-verifier setup with redundancy, despite LayerZero's recommendations. The incident highlights the importance of robust security configurations and the evolving threats posed by sophisticated attackers like Lazarus Group, which has been linked to over $575 million in DeFi losses in just 18 days.