LayerZero Points to Kelp's Security Setup as Cause of $290 Million Exploit, Links Attack to North Korea's Lazarus Group

LayerZero has attributed the $290 million Kelp DAO exploit to a security configuration issue on Kelp's part, stating that the protocol's single-verifier setup, which the company had warned against, made it vulnerable to the attack. The attackers, believed to be from North Korea's Lazarus Group, compromised two RPC nodes used by LayerZero's verifier and launched a DDoS attack on other nodes to force a failover, resulting in the release of 116,500 rsETH to the attackers. LayerZero emphasizes that the attack was only possible due to Kelp's use of a single-verifier setup, contrary to the company's recommendations for a multi-verifier configuration. The incident highlights the importance of robust security measures in DeFi protocols and the need for vigilance against evolving attack vectors.