Layerzero Discloses RPC Poisoning Incident Linked to $292M KelpDAO Hack
Layerzero Labs Apologizes for Lazarus Group Security Breach Response Layerzero Labs issued a candid apology for a three-week communication silence following a security breach involving the Lazarus Group. According to an official update, the attackers poisoned the source of truth for internal Remote Procedure Calls (RPCs) used by the Layerzero Labs Decentralized Verifier Network (DVN). This sophisticated hit coincided with a Distributed Denial of Service (DDoS) attack against the firms external RPC provider. The fallout, according to the report, was contained to a small fraction of the ecosystem. Layerzero noted that the incident impacted a single application, representing 0.14% of total apps and 0.36% of the total value locked on the protocol. Since April 19, the team detailed that it has been working with external security partners to finalize a comprehensive post-mortem report. The team further admitted to a significant oversight in allowing their DVN to act as a solo verifier for high-value transactions. Layerzero also acknowledged that they failed to police what their DVN was securing, which created a “single point of failure” risk. To rectify this, the lab is now educating developers on safe configurations and will no longer service 1/1 DVN setups. The disclosure also addressed a bizarre security lapse involving