LayerZero Labs Apologizes Over Security Incident, Outlines Fixes
LayerZero Labs said it is sorry for a security incident over the past three weeks and for inadequate communication, according to a statement posted on X.
The firm said its internal RPC was compromised by North Korea's Lazarus Group, contaminating DVN data sources. At the same time, external RPC providers faced DDoS attacks.
LayerZero said the event impacted one application, representing 0.14% of total usage, and involved assets equal to about 0.36% of total assets. The protocol itself was not affected, and roughly $9 billion in assets continued to move cross-chain normally following the incident.
The company also said allowing 1/1 single-node configurations created a single point of failure. It additionally disclosed a historical issue from about three and a half years ago related to multisig signers' misuse of hardware wallets.
Remedial steps include ending 1/1 DVN configurations, migrating to multisig setups, building a second DVN client, launching the OneSig tool, and rolling out the Console management platform.