LayerZero Attributes $290 Million Exploit to Kelp's Security Setup and North Korea's Lazarus Group

LayerZero has attributed the $290 million Kelp DAO exploit to Kelp's security configuration, stating that the protocol's single-verifier setup, which LayerZero had warned against, made it vulnerable to the attack. The exploit, which LayerZero believes with preliminary confidence was carried out by North Korea's Lazarus Group and its TraderTraitor subunit, involved compromising two remote procedure call (RPC) nodes used by LayerZero's verifier to confirm cross-chain transactions. The attackers replaced the binary software on these nodes with malicious versions that reported fraudulent transactions to LayerZero's verifier while providing accurate data to other systems. To ensure the attack went undetected, the attackers also launched a distributed denial-of-service (DDoS) attack on uncompromised external RPC nodes, forcing a failover to the compromised nodes. The DDoS attack, which occurred between 10:20 a.m. and 11:40 a.m. Pacific Time on Saturday, allowed the attackers to release 116,500 rsETH. The attack was only successful because Kelp used a 1-of-1 verifier configuration, contrary to LayerZero's recommendations for a multi-verifier setup with redundancy. LayerZero has confirmed that no other applications on the protocol were affected and has announced that it will no longer support single-verifier setups. The distinction between a protocol-level bug and a configuration failure is significant, as it implies that the protocol functioned as designed, and the exploit was the result of Kelp's security choices rather than a flaw in LayerZero's code. The Lazarus Group has been linked to two major exploits in 18 days, draining over $575 million from DeFi protocols through different attack vectors.