LayerZero Attributes $290 Million Kelp Exploit to Inadequate Security Setup and North Korean Hackers
LayerZero has attributed the $290 million Kelp DAO exploit to a security configuration flaw in Kelp's setup, specifically the use of a single-verifier configuration despite recommendations for a multi-verifier setup. The attack, which LayerZero believes with preliminary confidence was carried out by North Korea's Lazarus Group, involved compromising two remote procedure call (RPC) nodes that LayerZero's verifier relied on to confirm cross-chain transactions. The attackers then launched a distributed denial-of-service (DDoS) attack on other RPC nodes, forcing a failover to the compromised nodes and resulting in the release of 116,500 rsETH to the attackers. The attack's success was facilitated by Kelp's single-verifier configuration, which allowed the compromised nodes to forge a valid cross-chain message. LayerZero had previously recommended a multi-verifier setup with redundancy, which would have required consensus across several independent verifiers to confirm a message, thereby preventing the attack. The company has confirmed that there was no contagion to other applications on the protocol and has announced that it will no longer sign messages for applications running single-verifier configurations, effectively forcing a protocol-wide migration to multi-verifier setups. This distinction is significant for how DeFi protocols will assess LayerZero risk going forward, as the attack was the result of a configuration failure by a single integrator combined with a targeted infrastructure attack, rather than a protocol-level bug. The Lazarus Group has been linked to two major DeFi exploits in 18 days, including the Drift Protocol exploit on April 1, and has drained over $575 million from DeFi through two structurally different attack vectors.