LayerZero Points to Kelp's Security Setup as Cause of $290 Million Exploit, Links Attack to North Korea's Lazarus Group
LayerZero has attributed the $290 million exploit of Kelp DAO to a security lapse in Kelp's setup, specifically the use of a single-verifier configuration that the company had warned against. The attack, which LayerZero believes with preliminary confidence was conducted by North Korea's Lazarus Group, involved the compromise of two remote procedure call (RPC) nodes that LayerZero's verifier relied on for cross-chain transactions. These nodes were manipulated to report false data to LayerZero's verifier while providing accurate information to other systems, effectively hiding the attack from LayerZero's monitoring. To ensure the attack's success, the perpetrators also launched a distributed denial-of-service (DDoS) attack on uncompromised external RPC nodes, forcing a failover to the compromised nodes. This sophisticated attack resulted in the release of 116,500 rsETH to the attackers. LayerZero emphasizes that the attack's success was contingent upon Kelp's single-verifier setup, contrary to LayerZero's recommendations for a multi-verifier configuration that would have required consensus across several independent verifiers to confirm a message. The company has confirmed that there was no contagion to other applications on the protocol and has since brought its verifier back online, announcing that it will no longer support applications with single-verifier configurations. This distinction is crucial for how DeFi prices LayerZero risk, as the exploit was a result of Kelp's security choices and a targeted infrastructure attack rather than a protocol-level bug. Meanwhile, the Lazarus Group, linked to another recent exploit, has been accused of adapting its tactics faster than DeFi protocols can strengthen their defenses, highlighting a significant challenge for the industry.