LayerZero Points to Kelp's Security Setup as Cause of $290 Million Exploit, Links Attack to North Korea's Lazarus Group

LayerZero has attributed the $290 million Kelp DAO exploit to a security configuration issue on Kelp's part, stating that the protocol's single-verifier setup, which it had warned against, was the root cause of the vulnerability. The attack, which LayerZero believes with preliminary confidence was carried out by North Korea's Lazarus Group and its TraderTraitor subunit, involved the compromise of two RPC nodes that LayerZero's verifier relied on for cross-chain transaction verification. These nodes were manipulated to provide false information to LayerZero's verifier while maintaining accurate data for other systems, effectively hiding the attack from LayerZero's monitoring. To ensure the success of the exploit, the attackers also launched a distributed denial-of-service attack on uncompromised external RPC nodes, forcing a failover to the compromised nodes. Once the failover was triggered, the compromised nodes falsely verified a cross-chain message, resulting in the release of 116,500 rsETH to the attackers. The attack's success was contingent upon Kelp's use of a 1-of-1 verifier configuration, contrary to LayerZero's recommendations for a multi-verifier setup with redundancy. LayerZero has confirmed that there was no contagion to other applications on the protocol and has since taken the verifier offline, announcing that it will no longer support applications with single-verifier configurations. The distinction between a protocol-level bug and a configuration failure is significant, as it suggests that the protocol functioned as intended, and the vulnerability was the result of Kelp's security choices rather than a flaw in LayerZero's code. The Lazarus Group has been linked to another recent exploit, highlighting the group's adaptability and the need for DeFi protocols to enhance their defenses.