LayerZero Attributes $290 Million Exploit to Kelp's Security Setup and North Korea's Lazarus Group
LayerZero has attributed the responsibility for the $290 million Kelp DAO exploit to Kelp's security configuration, stating that the protocol's single-verifier setup, which LayerZero had previously advised against, made it vulnerable to the attack. The exploit, which LayerZero believes with preliminary confidence was carried out by North Korea's Lazarus Group and its TraderTraitor subunit, involved compromising two remote procedure call (RPC) nodes that LayerZero's verifier relied on for cross-chain transactions. These compromised nodes were made to report false data to LayerZero's verifier while continuing to provide accurate information to other systems, thus avoiding detection by LayerZero's monitoring infrastructure. To ensure the attack's success, the perpetrators also launched a distributed denial-of-service attack on uncompromised external RPC nodes, forcing a failover to the compromised ones. This elaborate scheme resulted in the release of 116,500 rsETH to the attackers. LayerZero emphasizes that the attack was only successful because Kelp operated a 1-of-1 verifier configuration, contrary to LayerZero's recommendations for a multi-verifier setup with redundancy. The company has confirmed that there was no contagion to other applications on the protocol and has since taken the LayerZero Labs verifier offline, announcing that it will no longer support applications with single-verifier configurations. This distinction is crucial as it separates the exploit from a potential protocol-level bug, indicating that the issue was with Kelp's security choices rather than LayerZero's code. The Lazarus Group, linked to another recent exploit, has now been implicated in draining over $575 million from DeFi protocols in just 18 days, highlighting the group's rapid adaptation of its attack strategies.