LayerZero Attributes $290 Million Kelp DAO Exploit to Inadequate Security Setup and North Korean Hackers

LayerZero has attributed the recent $290 million Kelp DAO exploit to the protocol's own security configuration, specifically its use of a single-verifier setup despite recommendations for a multi-verifier configuration. The attack, which LayerZero believes with preliminary confidence was carried out by North Korea's Lazarus Group, involved compromising two remote procedure call (RPC) nodes that LayerZero's verifier relied on to validate cross-chain transactions. The attackers then used these compromised nodes to deceive LayerZero's verifier into confirming a fraudulent transaction, while simultaneously conducting a distributed denial-of-service (DDoS) attack on other external RPC nodes to force failover to the compromised ones. This DDoS attack, which occurred between 10:20 a.m. and 11:40 a.m. Pacific Time on Saturday, ultimately led to the release of 116,500 rsETH to the attackers. The malicious node software subsequently self-destructed, wiping binaries and local logs. LayerZero emphasizes that this attack would not have been successful if Kelp had implemented a multi-verifier setup, which would have required consensus across several independent verifiers to confirm a message. The company has confirmed that there was no contagion to other applications on the protocol and that all OFT-standard tokens and applications running multi-verifier setups were unaffected. In response to the incident, LayerZero has announced that it will no longer sign messages for applications running single-verifier configurations, effectively forcing a protocol-wide migration to more secure multi-verifier setups. This distinction is significant, as it implies that the protocol itself functioned as designed, and the exploit was the result of Kelp's security choices rather than a flaw in LayerZero's code. The Lazarus Group, which has been linked to another recent DeFi exploit, has now drained over $575 million from DeFi protocols in just 18 days through two distinct attack vectors, highlighting the group's ability to adapt its tactics faster than DeFi protocols can strengthen their defenses.