LayerZero Attributes $290 Million Kelp Exploit to Single-Verifier Setup and North Korea's Lazarus Group

LayerZero has attributed the $290 million exploit of Kelp DAO to Kelp's security configuration, specifically the use of a single-verifier setup. The attack, which LayerZero believes with preliminary confidence was carried out by North Korea's Lazarus Group and its TraderTraitor subunit, involved the compromise of two remote procedure call (RPC) nodes used by LayerZero's verifier to confirm cross-chain transactions. The attackers replaced the binary software on these nodes with malicious versions that reported fraudulent transactions to LayerZero's verifier while maintaining accurate data for other systems. To ensure the attack went undetected, the attackers launched a distributed denial-of-service attack on uncompromised external RPC nodes, forcing a failover to the compromised nodes. The attack resulted in the release of 116,500 rsETH to the attackers. LayerZero emphasizes that the attack was only successful due to Kelp's 1-of-1 verifier configuration, contrary to LayerZero's recommendations for a multi-verifier setup. The company has confirmed no contagion to other applications on the protocol and has since taken the LayerZero Labs verifier offline, announcing it will no longer sign messages for applications with single-verifier configurations. This distinction is crucial for how DeFi prices LayerZero risk, as the exploit was the result of a configuration failure by Kelp rather than a protocol-level bug. The Lazarus Group has been linked to two significant exploits in 18 days, totaling over $575 million, highlighting the group's rapid adaptation of its attack strategies.