LayerZero Points to Kelp's Security Setup as Culprit in $290 Million Hack, Citing Lazarus Group Involvement
LayerZero has attributed the $290 million Kelp DAO hack to a security configuration flaw on Kelp's part, stating that the protocol's single-verifier setup, despite previous warnings, allowed attackers to compromise two RPC nodes and orchestrate a DDoS attack on others. The attackers, believed with preliminary confidence to be linked to North Korea's Lazarus Group, manipulated the nodes to deceive LayerZero's verifier into confirming a fraudulent transaction. This was achieved by replacing the binary software on the compromised nodes with malicious versions that reported false data to LayerZero's verifier while maintaining accurate reports to other systems. To ensure the attack remained undetected by LayerZero's monitoring, which uses different IP addresses to query the RPCs, the attackers launched a DDoS attack on the uncompromised external RPC nodes, forcing a failover to the compromised ones. Logs show the DDoS occurred between 10:20 a.m. and 11:40 a.m. Pacific Time on Saturday, resulting in the release of 116,500 rsETH to the attackers. The success of the attack was directly tied to Kelp's use of a 1-of-1 verifier configuration, contrary to LayerZero's recommendations for a multi-verifier setup that would have required consensus across several independent verifiers to confirm a message. LayerZero has confirmed that no other applications on the protocol were affected, thanks to their use of multi-verifier setups, and has announced that it will no longer support applications with single-verifier configurations. The distinction between a protocol-level bug and a configuration failure is significant for how DeFi assesses LayerZero's risk. While a protocol-level issue would have implied a broader risk to all OFT tokens, the fact that the exploit was due to Kelp's security choices and a targeted infrastructure attack suggests that the protocol functioned as designed. Kelp has not publicly addressed LayerZero's assertions or its decision to operate a 1-of-1 verifier setup despite warnings. The Lazarus Group, linked to both the Kelp and Drift Protocol exploits, has drained over $575 million from DeFi in 18 days, demonstrating an alarming adaptability in its attack strategies.