LayerZero Attributes $290 Million Kelp Exploit to Inadequate Security Setup and North Korea's Lazarus Group

LayerZero has stated that the $290 million exploit of Kelp DAO is a direct result of Kelp's security configuration, specifically its use of a single-verifier setup, which LayerZero had previously advised against. The attackers, believed to be associated with North Korea's Lazarus Group, compromised two remote procedure call (RPC) nodes used by LayerZero's verifier to confirm cross-chain transactions. By swapping the binary software on these nodes with malicious versions, the attackers were able to deceive LayerZero's verifier into believing a fraudulent transaction had occurred, while still reporting accurate data to other systems. To ensure the attack went undetected, the attackers also launched a distributed denial-of-service attack on uncompromised external RPC nodes, forcing a failover to the compromised nodes. Once the failover was triggered, the compromised nodes informed the verifier that a valid cross-chain message had been received, resulting in the release of 116,500 rsETH to the attackers. The malicious node software then self-destructed, removing any evidence. This exploit was only possible due to Kelp's 1-of-1 verifier configuration, where LayerZero Labs was the sole entity verifying messages. LayerZero had recommended a multi-verifier setup with redundancy, which would have required consensus across several independent verifiers to confirm a message, thereby preventing the attack. The company has confirmed that there was no contagion to any other application on the protocol and that every OFT-standard token and application using multi-verifier setups was unaffected. As a result, LayerZero will no longer sign messages for applications using a 1-of-1 configuration, prompting a protocol-wide migration away from single-verifier setups. This distinction is crucial for how DeFi assesses LayerZero risk moving forward, as it was a configuration failure by Kelp, combined with a targeted infrastructure attack, rather than a protocol-level bug, that created the vulnerability. Kelp has yet to publicly respond to LayerZero's account of the events or explain why it operated a 1-of-1 verifier setup despite explicit recommendations against it. The Lazarus Group, linked to the recent Drift Protocol exploit, has now drained over $575 million from DeFi in 18 days through two distinct attack vectors, highlighting the group's rapid adaptation of its strategies and the need for DeFi protocols to enhance their defenses.