LayerZero Points to Kelp's Security Setup as Cause of $290 Million Exploit, Links Attack to North Korea's Lazarus Group
LayerZero has attributed the $290 million exploit of Kelp DAO to a security configuration issue on Kelp's part, stating that the protocol's single-verifier setup, which LayerZero had previously advised against, was the root cause of the vulnerability. The attack, which LayerZero believes with preliminary confidence was carried out by North Korea's Lazarus Group and its TraderTraitor subunit, involved the compromise of two remote procedure call (RPC) nodes that LayerZero's verifier relied on for cross-chain transactions. These nodes were manipulated to report false transaction data to LayerZero's verifier while maintaining accurate data for other systems, thus avoiding detection by LayerZero's monitoring infrastructure. To ensure the attack's success, the perpetrators also launched a distributed denial-of-service attack on uncompromised external RPC nodes, forcing a failover to the compromised nodes. Once the failover was triggered, the compromised nodes falsely reported a valid cross-chain message, resulting in the release of 116,500 rsETH to the attackers. The malicious software then self-destructed, erasing binaries and local logs. This exploit was only possible due to Kelp's 1-of-1 verifier configuration, contrary to LayerZero's recommendations for a multi-verifier setup with redundancy. Such a setup would have required consensus across multiple independent verifiers to confirm a message, thereby preventing the forging of a valid message through the poisoning of a single verifier's data feed. LayerZero has confirmed that there was no contagion to other applications on the protocol, with all OFT-standard tokens and applications using multi-verifier setups remaining unaffected. In response, LayerZero Labs has brought its verifier back online and will no longer sign messages for applications with single-verifier configurations, effectively necessitating a protocol-wide migration to multi-verifier setups. This distinction is significant for how DeFi assesses LayerZero risk, as it indicates the protocol functioned as designed, with the exploit resulting from Kelp's security choices rather than a flaw in LayerZero's code. Kelp has yet to publicly address LayerZero's account of the events or explain its decision to operate a 1-of-1 verifier setup despite explicit warnings against such a configuration. The Lazarus Group, linked to both the Kelp exploit and the earlier Drift Protocol exploit, has drained over $575 million from DeFi in 18 days through two distinct attack vectors, highlighting the group's rapid adaptation of its tactics and the need for DeFi protocols to enhance their defenses.