Skip to content

LayerZero Blames Kelp for $290M Exploit

LayerZero Attributes $290 Million Kelp DAO Exploit to Security Configuration Failures

  • The Kelp DAO exploit resulted in a loss of $290 million, attributed to its single-verifier setup.
  • LayerZero identified the attackers as likely linked to North Korea’s Lazarus Group, responsible for over $575 million in DeFi exploits within weeks.
  • The attack involved compromising two remote procedure call (RPC) nodes, allowing attackers to manipulate transaction confirmations.
  • A distributed denial-of-service (DDoS) attack was executed on uncompromised nodes to force failover to the poisoned ones.
  • Kelp’s configuration did not follow LayerZero’s recommendations for a multi-verifier setup, which would have mitigated this risk.

LayerZero confirmed that no other applications on its protocol were affected by this exploit, indicating that the issue was isolated to Kelp’s security choices rather than a flaw in LayerZero’s code.

This incident highlights the importance of robust security configurations in DeFi, especially as Kelp’s single-verifier setup led directly to the loss of $290 million. (Source)

Share