LayerZero Attributes $290 Million Kelp Exploit to Poor Security Setup, Links Attack to North Korea's Lazarus Group

LayerZero has attributed the $290 million exploit of Kelp DAO to a security configuration issue, stating that Kelp's use of a single-verifier setup made the attack possible. The exploit was carried out by compromising two remote procedure call (RPC) nodes used by LayerZero's verifier to confirm cross-chain transactions. These nodes were swapped with malicious versions that reported fraudulent transactions to LayerZero's verifier while maintaining accurate data for other systems. To ensure the attack went undetected, the attackers launched a distributed denial-of-service (DDoS) attack on uncompromised external RPC nodes, forcing a failover to the compromised nodes. Once the failover was triggered, the compromised nodes reported a valid cross-chain message, resulting in the release of 116,500 rsETH to the attackers. The attack was only successful due to Kelp's 1-of-1 verifier configuration, which LayerZero had previously warned against, recommending a multi-verifier setup with redundancy instead. LayerZero has confirmed that the attack did not affect any other applications on the protocol and has taken steps to prevent similar attacks in the future, including refusing to sign messages for applications with single-verifier setups. The exploit has been linked to North Korea's Lazarus Group, which has been responsible for over $575 million in DeFi losses in the past 18 days.