LayerZero Attributes $290 Million Kelp Exploit to Poor Security Setup and North Korean Hackers
LayerZero has attributed the $290 million exploit of Kelp DAO to the protocol's own security configuration, specifically its single-verifier setup, which LayerZero had previously advised against. The attackers, believed to be North Korea's Lazarus Group, compromised two remote procedure call (RPC) nodes used by LayerZero's verifier to confirm cross-chain transactions. By replacing the binary software on these nodes with malicious versions, the attackers were able to deceive LayerZero's verifier into confirming a fraudulent transaction. To prevent detection, the attackers also launched a distributed denial-of-service (DDoS) attack on uncompromised external RPC nodes, forcing failover to the compromised nodes. The attack was only successful because Kelp had not implemented a multi-verifier setup with redundancy, as recommended by LayerZero. The company has confirmed that there was no contagion to other applications on the protocol and has taken steps to prevent similar attacks in the future, including refusing to sign messages for applications with single-verifier setups. The incident highlights the importance of robust security configurations and the evolving threat landscape in the DeFi space, with Lazarus Group linked to over $575 million in losses from two recent exploits.