LayerZero Attributes $290 Million Kelp Exploit to Single-Verifier Setup and Lazarus Group

LayerZero has attributed the $290 million Kelp DAO exploit to Kelp's security configuration, specifically the use of a single-verifier setup despite previous warnings. The attack, which LayerZero believes with preliminary confidence was carried out by North Korea's Lazarus Group, involved compromising two RPC nodes that LayerZero's verifier relied on, and then launching a DDoS attack on the remaining nodes to force a failover to the compromised ones. This allowed the attackers to trick LayerZero's verifier into releasing 116,500 rsETH. The attack was only possible due to Kelp's 1-of-1 verifier configuration, which LayerZero had recommended against in favor of a multi-verifier setup with redundancy. LayerZero has confirmed that there was no contagion to other applications on the protocol and has since taken the LayerZero Labs verifier offline for applications running single-verifier setups. The exploit has significant implications for how DeFi prices LayerZero risk, as it was a configuration failure by Kelp rather than a protocol-level bug that created the vulnerability. Lazarus Group has been linked to two major DeFi exploits in 18 days, draining over $575 million.