LayerZero Points to Kelp's Security Setup as Cause of $290 Million Exploit, Links Attack to North Korea's Lazarus Group

LayerZero has attributed the $290 million exploit of Kelp DAO to a security configuration issue on Kelp's part, stating that the protocol's single-verifier setup, which LayerZero had previously advised against, was the root cause of the vulnerability. The attack, which LayerZero believes with preliminary confidence was carried out by North Korea's Lazarus Group and its TraderTraitor subunit, involved the compromise of two remote procedure call (RPC) nodes that LayerZero's verifier relied on for cross-chain transactions. These nodes were manipulated to provide false information to LayerZero's verifier while maintaining accurate data for other systems, effectively masking the attack from LayerZero's monitoring infrastructure. To ensure the attack's success, the perpetrators also launched a distributed denial-of-service (DDoS) attack on uncompromised external RPC nodes, forcing a failover to the compromised nodes. This DDoS attack, which occurred between 10:20 a.m. and 11:40 a.m. Pacific Time on Saturday, allowed the attackers to release 116,500 rsETH. The malicious software used in the attack was designed to self-destruct, eliminating binaries and local logs. LayerZero emphasizes that the attack was only possible due to Kelp's 1-of-1 verifier configuration, contrary to LayerZero's recommendations for a multi-verifier setup that would require consensus across several independent verifiers to confirm a message. Such a setup would have prevented the attack, as poisoning one verifier's data feed would not have been sufficient to forge a valid message. LayerZero has confirmed that there was no contagion to other applications on the protocol and that all OFT-standard tokens and applications using multi-verifier setups were unaffected. In response, LayerZero Labs has brought its verifier back online and will no longer support applications with single-verifier configurations, prompting a protocol-wide migration to more secure setups. This distinction is crucial for how DeFi assesses LayerZero risk, as a protocol-level bug would have implied a broader risk, whereas the configuration failure and targeted infrastructure attack suggest the protocol functioned as designed, with Kelp's security choices being the vulnerability. Kelp has yet to publicly address LayerZero's account of the exploit or explain its decision to operate a 1-of-1 verifier setup despite explicit recommendations against it. The Lazarus Group, linked to both the Kelp and Drift Protocol exploits, has drained over $575 million from DeFi in 18 days, demonstrating its ability to adapt its attack strategies faster than DeFi protocols can fortify their defenses.