LayerZero Attributes $290 Million Kelp Exploit to Inadequate Security Setup, Points to North Korea's Lazarus Group
LayerZero has identified Kelp's security configuration as the primary cause of the $290 million exploit, stating that the protocol's single-verifier setup, which LayerZero had previously advised against, was the key factor that allowed the attack to succeed. The attackers, believed with preliminary confidence to be associated with North Korea's Lazarus Group and its TraderTraitor subunit, managed to compromise two of the remote procedure call (RPC) nodes that LayerZero's verifier relied on. These nodes are crucial as they enable software to read and write data on a blockchain, and LayerZero's verifier utilized a combination of internal and external nodes for redundancy. The attackers replaced the legitimate binary software on the compromised nodes with malicious versions, designed to deceive LayerZero's verifier into confirming a fraudulent transaction while providing accurate data to other systems. To ensure the attack remained undetected by LayerZero's monitoring infrastructure, the attackers implemented a selective lying mechanism. However, compromising two nodes was insufficient, as LayerZero's verifier also queried uncompromised external RPC nodes. Therefore, the attackers launched a distributed denial-of-service (DDoS) attack on those nodes to force a failover to the compromised ones. LayerZero shared traffic logs indicating the DDoS occurred between 10:20 a.m. and 11:40 a.m. Pacific Time on Saturday. Once the failover was triggered, the compromised nodes misled the verifier into believing a valid cross-chain message had been received, resulting in Kelp's bridge releasing 116,500 rsETH to the attackers. The malicious node software then self-destructed, removing binaries and local logs. The success of the attack was directly attributed to Kelp's 1-of-1 verifier configuration, where LayerZero Labs was the sole entity verifying messages to and from the rsETH bridge. This setup was contrary to LayerZero's public integration checklist and direct communications to Kelp, which recommended a multi-verifier setup with redundancy. Such a configuration would have required consensus across several independent verifiers to confirm a message, thereby preventing the attack. LayerZero confirmed that there was no contagion to any other application on the protocol, with all OFT-standard tokens and applications running multi-verifier setups remaining unaffected. The LayerZero Labs verifier is now back online, and the company has announced it will no longer sign messages for applications operating with a 1-of-1 configuration, effectively mandating a protocol-wide migration away from single-verifier setups. This distinction is crucial for how DeFi assesses LayerZero risk moving forward, as it differentiates between a protocol-level bug and a configuration failure by a single integrator combined with a targeted infrastructure attack. The latter implies that the protocol functioned as designed, and it was Kelp's security choices, rather than LayerZero's code, that created the vulnerability. Kelp has yet to publicly address LayerZero's account of the events or explain why it opted for a 1-of-1 verifier setup despite explicit recommendations against it. The Lazarus Group has been linked to two significant exploits in a short span - the Drift Protocol exploit on April 1 and the Kelp exploit on April 18 - collectively draining over $575 million from DeFi in 18 days through distinct attack vectors, highlighting the group's rapid adaptation of its strategies.