LayerZero reports KelpDAO theft incident, confirms it only affected RsETH configuration

robot
Abstract generation in progress

Mars Finance reports that LayerZero Labs released a statement on the attack incident, stating that KelpDAO was attacked with losses of approximately $290 million. The preliminary assessment suggests the attacker is Lazarus Group with a North Korean background (more specifically TraderTraitor). The attack was carried out by poisoning the downstream RPC infrastructure that their decentralized verification network (DVN) depends on, with the attacker controlling some RPC nodes and coordinating a DDoS attack to induce the system to switch to malicious nodes, thereby forging cross-chain transactions. All affected RPC nodes have been taken offline and replaced, and the DVN has now resumed operation. LayerZero emphasized that this incident was limited to KelpDAO’s rsETH application configuration and did not impact other assets or applications. The reason is that KelpDAO was using a single DVN (1/1) architecture at the time and did not employ the officially recommended multi-DVN redundancy mechanism, which led to a lack of independent verification nodes to identify forged messages. LayerZero pointed out that their protocol itself was not vulnerable, and applications with multi-DVN configurations were unaffected;

View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pin