LayerZero Attributes $290 Million Kelp Exploit to Inadequate Security Setup, Links Attack to North Korea's Lazarus Group
LayerZero has assigned blame for the $290 million Kelp DAO exploit to the protocol's own security configuration, stating that Kelp's use of a single-verifier setup made it vulnerable to attack. The attackers, believed to be North Korea's Lazarus Group, compromised two RPC nodes that LayerZero's verifier relied on, allowing them to deceive the verifier into confirming a fraudulent transaction. The attack was only successful because Kelp ignored recommendations to implement a multi-verifier setup. LayerZero's verifier used a combination of internal and external RPC nodes for redundancy, but the attackers were able to swap the binary software on two of the nodes with malicious versions. The attackers then launched a distributed denial-of-service attack on the uncompromised external RPC nodes, forcing failover to the compromised nodes. Once the failover was triggered, the compromised nodes told the verifier that a valid cross-chain message had arrived, resulting in the release of 116,500 rsETH to the attackers. The malicious node software then self-destructed, wiping binaries and local logs. LayerZero has confirmed that there was no contagion to any other application on the protocol and has stated that it will no longer sign messages for applications running a 1-of-1 configuration. The company has also emphasized that the attack was a result of Kelp's security choices, rather than any flaw in LayerZero's code. The Lazarus Group has been linked to two major DeFi exploits in the past 18 days, draining over $575 million from DeFi protocols through structurally different attack vectors.