LayerZero Pins $290 Million Kelp DAO Exploit on Kelp's Security Setup, Links Attack to North Korea's Lazarus Group
LayerZero has attributed the $290 million Kelp DAO exploit to Kelp's own security configuration, stating that the protocol's single-verifier setup, which LayerZero had warned against, was the primary cause of the vulnerability. The attack, which LayerZero believes with preliminary confidence was carried out by North Korea's Lazarus Group and its TraderTraitor subunit, involved compromising two remote procedure call (RPC) nodes that LayerZero's verifier relied on. These nodes were tricked into reporting false data to LayerZero's verifier while continuing to provide accurate information to other systems. To ensure the attack remained undetected, the attackers launched a distributed denial-of-service (DDoS) attack on uncompromised external RPC nodes, forcing LayerZero's verifier to failover to the compromised nodes. The DDoS attack, which occurred between 10:20 a.m. and 11:40 a.m. Pacific Time on Saturday, allowed the attackers to release 116,500 rsETH. LayerZero's traffic logs confirm the DDoS attack and the subsequent failover. The company emphasizes that the attack was only successful because Kelp used a 1-of-1 verifier configuration, contrary to LayerZero's recommendations for a multi-verifier setup with redundancy. Such a setup would have required consensus across several independent verifiers to confirm a message, thereby preventing the attack. LayerZero has confirmed that there was no contagion to other applications on the protocol and that all OFT-standard tokens and applications using multi-verifier setups were unaffected. In response to the incident, LayerZero Labs has brought its verifier back online and will no longer sign messages for applications with single-verifier configurations, effectively enforcing a protocol-wide migration to multi-verifier setups. This distinction is crucial for how DeFi prices LayerZero risk, as it indicates that the protocol functioned as designed and that Kelp's security choices, rather than LayerZero's code, created the vulnerability. The Lazarus Group has been linked to two significant DeFi exploits in 18 days, including the Drift Protocol exploit on April 1 and the Kelp exploit on April 18, resulting in the drainage of over $575 million from DeFi through structurally different attack vectors.