LayerZero Attributes $290 Million Kelp Exploit to Inadequate Security Setup and North Korea's Lazarus Group
LayerZero has attributed the $290 million Kelp DAO exploit to Kelp's own security configuration, stating that the protocol's single-verifier setup, which was previously warned against, was the primary factor in the attack. The novel attack vector targeted the infrastructure layer, compromising two RPC nodes that LayerZero's verifier relied on. The attackers, believed to be North Korea's Lazarus Group, swapped the binary software on these nodes with malicious versions, which reported fraudulent transactions to LayerZero's verifier while maintaining accurate data for other systems. To ensure the attack went undetected, the attackers launched a distributed denial-of-service attack on uncompromised external RPC nodes, forcing a failover to the compromised nodes. Once the failover was triggered, the compromised nodes confirmed a valid cross-chain message, resulting in the release of 116,500 rsETH to the attackers. The attack's success can be directly linked to Kelp's 1-of-1 verifier configuration, which LayerZero had advised against, recommending a multi-verifier setup with redundancy instead. LayerZero has confirmed that there was no contagion to other applications on the protocol and has since brought its verifier back online, announcing that it will no longer sign messages for applications running single-verifier configurations. This incident highlights the importance of security configurations and the evolving nature of attacks in the DeFi space, with Lazarus Group linked to over $575 million in losses from two recent exploits.