LayerZero Attributes $290 Million Kelp Exploit to Inadequate Security Setup and North Korea's Lazarus Group
LayerZero has attributed the $290 million exploit of Kelp DAO to the protocol's single-verifier configuration, which disregarded the company's recommendations for a multi-verifier setup. The attackers, believed to be associated with North Korea's Lazarus Group, compromised two RPC nodes relied upon by LayerZero's verifier and launched a DDoS attack on other nodes to force a failover. This attack vector, targeting the infrastructure layer rather than protocol code, allowed the attackers to deceive LayerZero's verifier into releasing 116,500 rsETH. The success of the attack was contingent upon Kelp's decision to operate a 1-of-1 verifier configuration, contrary to LayerZero's advice for redundancy through multiple verifiers. LayerZero has confirmed that the attack did not affect any other applications on the protocol and has since taken measures to prevent similar incidents by refusing to sign messages for applications with single-verifier setups. The distinction between a protocol-level bug and a configuration failure is crucial for assessing LayerZero risk, with the latter implying that the protocol functioned as designed and the security lapse was due to Kelp's choices.