LayerZero Attributes $290 Million Exploit to Kelp's Security Setup and North Korea's Lazarus Group

LayerZero has attributed the $290 million Kelp DAO exploit to Kelp's own security configuration, specifically its use of a single-verifier setup that the company had warned against. The attack was carried out by compromising two RPC nodes that LayerZero's verifier relied on, with preliminary evidence pointing to North Korea's Lazarus Group and its TraderTraitor subunit as the perpetrators. The attackers replaced the binary software on these nodes with malicious versions designed to deceive LayerZero's verifier into confirming a fraudulent transaction, while still reporting accurate data to other systems. To ensure the attack went undetected, the attackers launched a distributed denial-of-service attack on uncompromised external RPC nodes, forcing failover to the compromised ones. The attack's success was contingent upon Kelp's single-verifier configuration, which LayerZero had recommended against in favor of a multi-verifier setup with redundancy. The company has confirmed that no other applications on the protocol were affected and has since brought its verifier back online, announcing that it will no longer support single-verifier configurations. This incident highlights the importance of security configurations and the evolving threat landscape in DeFi, with Lazarus Group linked to over $575 million in exploits in just 18 days.