LayerZero Pins $290 Million Exploit on Kelp's Security Setup, Links Attack to North Korea's Lazarus Group
LayerZero attributes the recent $290 million Kelp DAO exploit to a security configuration flaw on Kelp's part, specifically the use of a single-verifier setup despite recommendations for a multi-verifier configuration. The attack, which LayerZero believes with preliminary confidence was conducted by North Korea's Lazarus Group, involved compromising two RPC nodes that LayerZero's verifier relied on for cross-chain transactions. These nodes were manipulated to report false transaction data to LayerZero's verifier while appearing normal to other systems. To ensure the attack's success, the perpetrators also launched a distributed denial-of-service attack on other, uncompromised RPC nodes, forcing a failover to the compromised nodes. This sophisticated attack resulted in the release of 116,500 rsETH to the attackers. LayerZero emphasizes that the exploit was only possible due to Kelp's single-verifier setup and notes that its own protocol functioned as designed. The company has confirmed no contagion to other applications and will no longer support single-verifier configurations, pushing for a protocol-wide migration to multi-verifier setups for enhanced security.