LayerZero Attributes $290 Million Kelp Exploit to North Korea's Lazarus Group, Citing Kelp's Security Setup

LayerZero has attributed the $290 million exploit of Kelp DAO to Kelp's own security configuration, specifically a single-verifier setup that the company had warned against. The attack, which LayerZero believes with preliminary confidence was carried out by North Korea's Lazarus Group and its TraderTraitor subunit, involved compromising two remote procedure call (RPC) nodes that LayerZero's verifier relied on for cross-chain transactions. The attackers then used these compromised nodes to feed false information to LayerZero's verifier, while continuing to provide accurate data to other systems, thereby avoiding detection. To ensure the attack's success, the perpetrators also launched a distributed denial-of-service attack on uncompromised external RPC nodes, forcing a failover to the compromised ones. This allowed the attackers to release 116,500 rsETH. The attack's success is attributed to Kelp's 1-of-1 verifier configuration, which LayerZero had recommended against in favor of a multi-verifier setup for added security. LayerZero has confirmed that no other applications on the protocol were affected and has since taken the LayerZero Labs verifier offline for applications running single-verifier setups, prompting a protocol-wide migration to multi-verifier configurations. The distinction between a protocol-level bug and a configuration failure is significant for how DeFi prices LayerZero risk. Meanwhile, Lazarus Group has been linked to over $575 million in DeFi exploits in just 18 days, highlighting the group's rapid adaptation of its attack strategies.