LayerZero Attributes $290 Million Kelp Exploit to Inadequate Security Setup, Points to North Korea's Lazarus Group

LayerZero has attributed the $290 million Kelp DAO exploit to Kelp's own security configuration, stating that the protocol's single-verifier setup, despite previous warnings, allowed for the breach. The attack, preliminarily linked to North Korea's Lazarus Group, involved compromising two remote procedure call (RPC) nodes used by LayerZero's verifier for cross-chain transactions. These nodes were manipulated to report false transaction data to LayerZero's verifier while maintaining accurate data for other systems. To ensure the attack went undetected by LayerZero's monitoring, which queries the same RPCs from different IP addresses, the attackers conducted a distributed denial-of-service (DDoS) attack on uncompromised external RPC nodes, forcing a failover to the compromised ones. Logs show the DDoS occurred between 10:20 a.m. and 11:40 a.m. Pacific Time on Saturday, resulting in the release of 116,500 rsETH to the attackers. The attack's success was facilitated by Kelp's 1-of-1 verifier configuration, which LayerZero had recommended against in favor of a multi-verifier setup for added redundancy and security. LayerZero emphasized that the attack only worked due to Kelp's configuration and not due to any flaw in LayerZero's protocol code. The company confirmed no contagion to other applications on the protocol and has since brought its verifier back online, announcing it will no longer support applications with single-verifier setups. This incident highlights the importance of security configurations in DeFi protocols and the evolving tactics of hacking groups like Lazarus, which has been linked to over $575 million in DeFi exploits in just 18 days.