LayerZero Attributes $290 Million Exploit to Kelp's Security Setup and North Korea's Lazarus Group

LayerZero has attributed the $290 million Kelp DAO exploit to Kelp's own security configuration, stating that the protocol's single-verifier setup, which LayerZero had warned against, was the primary cause of the attack. The exploit, which LayerZero believes with preliminary confidence was carried out by North Korea's Lazarus Group and its TraderTraitor subunit, involved the compromise of two remote procedure call (RPC) nodes that LayerZero's verifier relied on. These nodes were manipulated to report fraudulent transactions to LayerZero's verifier while maintaining accurate data for other systems. To ensure the attack remained undetected, the perpetrators launched a distributed denial-of-service (DDoS) attack on uncompromised external RPC nodes, forcing a failover to the compromised nodes. Once the failover was triggered, the compromised nodes informed the verifier that a valid cross-chain message had been received, resulting in the release of 116,500 rsETH to the attackers. The malicious node software then self-destructed, erasing binaries and local logs. LayerZero emphasizes that the attack was successful only because Kelp operated a 1-of-1 verifier configuration, contrary to LayerZero's recommendations for a multi-verifier setup with redundancy. Such a setup would have required consensus across multiple independent verifiers to confirm a message, thereby preventing the attack. LayerZero has confirmed that there was no contagion to other applications on the protocol and has announced that it will no longer sign messages for applications running single-verifier configurations, prompting a protocol-wide migration to multi-verifier setups. The distinction between a protocol-level bug and a configuration failure is significant, as it implies that the protocol functioned as designed, and the vulnerability was due to Kelp's security choices rather than LayerZero's code. Lazarus Group, linked to the Drift Protocol exploit on April 1, has now been implicated in the Kelp exploit on April 18, resulting in the drainage of over $575 million from DeFi in 18 days through two distinct attack vectors.