LayerZero Labs reported on the X platform that its internal RPC was targeted by the Lazarus Group over the past three weeks, compromising the real source of its Decentralized Verification Network (DVN). According to Odaily, external RPC providers also faced DDOS attacks, affecting 0.14% of applications and approximately 0.36% of asset value. LayerZero Labs assured that assets are currently secure, with over $9 billion having been transferred across the protocol since April 19.
In response to the security risks, LayerZero Labs has ceased offering 1/1 configuration services for its DVN, transitioning all default configurations to at least 3/3 or 5/5 multi-DVN modes. Additionally, following an incident three years ago involving the misuse of a hardware wallet by a multi-signature holder for personal transactions, the company has removed the signer and replaced the wallet. They have also developed a custom multi-signature system called OneSig.
LayerZero Labs advises developers to lock configurations to avoid reliance on default settings and plans to launch an asset management platform, Console, to enhance security monitoring.