LayerZero Attributes $290 Million Kelp Exploit to Inadequate Security Setup and North Korea's Lazarus Group
LayerZero has attributed the recent $290 million exploit of Kelp DAO to the protocol's insecure configuration, specifically its use of a single-verifier setup despite recommendations for a multi-verifier configuration. The attack, which LayerZero believes with preliminary confidence was carried out by North Korea's Lazarus Group, involved the compromise of two RPC nodes used by LayerZero's verifier to confirm cross-chain transactions. These nodes were manipulated to report false data to LayerZero's verifier while continuing to provide accurate information to other systems, thus avoiding detection by LayerZero's monitoring infrastructure. To ensure the attack's success, the perpetrators also launched a distributed denial-of-service (DDoS) attack on uncompromised external RPC nodes, forcing a failover to the compromised nodes. The DDoS attack took place between 10:20 a.m. and 11:40 a.m. Pacific Time on Saturday, as shown in traffic logs shared by LayerZero. Once the compromised nodes were used, they reported a valid cross-chain message to Kelp's bridge, resulting in the release of 116,500 rsETH to the attackers. The malicious software then self-destructed, erasing binaries and local logs. LayerZero emphasizes that the attack was only possible due to Kelp's 1-of-1 verifier configuration, where LayerZero Labs was the sole entity verifying messages to and from the rsETH bridge. In contrast, a multi-verifier setup with redundancy, as recommended by LayerZero, would have required consensus across several independent verifiers to confirm a message, thereby preventing the attack. LayerZero has confirmed that there was no contagion to any other application on the protocol, with all OFT-standard tokens and applications running multi-verifier setups remaining unaffected. In response to the incident, LayerZero Labs has resumed operations and will no longer sign messages for applications using a 1-of-1 configuration, effectively requiring a protocol-wide migration to multi-verifier setups. This distinction is significant for how DeFi prices LayerZero risk, as it highlights that the exploit resulted from a configuration failure by a single integrator combined with a targeted infrastructure attack, rather than a protocol-level bug. Kelp has yet to publicly address LayerZero's account of the incident or explain why it operated a 1-of-1 verifier setup despite explicit recommendations against it. The Lazarus Group, attributed to the exploit, has been linked to another recent attack on the Drift Protocol, totaling over $575 million drained from DeFi in 18 days through two distinct attack vectors.