LayerZero Pins $290 Million Kelp Exploit on Kelp's Security Setup, Links Attack to North Korea's Lazarus Group

LayerZero has attributed the $290 million Kelp DAO exploit to Kelp's own security configuration, stating that the protocol's single-verifier setup, which LayerZero had previously advised against, was the root cause of the breach. The attack, which LayerZero believes with preliminary confidence was carried out by North Korea's Lazarus Group and its TraderTraitor subunit, involved the compromise of two remote procedure call (RPC) nodes that LayerZero's verifier relied on for cross-chain transactions. These nodes were manipulated to report fraudulent transactions to LayerZero's verifier while providing accurate data to other systems, effectively masking the attack from LayerZero's monitoring infrastructure. To ensure the attack's success, the perpetrators also launched a distributed denial-of-service (DDoS) attack on uncompromised external RPC nodes, forcing a failover to the compromised nodes. The DDoS, which occurred between 10:20 a.m. and 11:40 a.m. Pacific Time on Saturday, allowed the attackers to release 116,500 rsETH. The malicious node software then self-destructed, erasing binaries and local logs. LayerZero emphasizes that the attack was only possible due to Kelp's 1-of-1 verifier configuration, contrary to LayerZero's recommendations for a multi-verifier setup with redundancy. Such a setup would have required consensus across multiple independent verifiers to confirm a message, thereby preventing the attack. LayerZero has confirmed that there was no contagion to other applications on the protocol and that all OFT-standard tokens and applications using multi-verifier setups were unaffected. The company has resumed its verifier services but will no longer support applications with single-verifier configurations, prompting a protocol-wide migration to more secure setups. This distinction is crucial for how DeFi assesses LayerZero risk, as the exploit resulted from a configuration failure and targeted infrastructure attack rather than a protocol-level bug. Kelp has not publicly responded to LayerZero's account or explained its decision to operate a 1-of-1 verifier setup despite explicit recommendations against it. The Lazarus Group, linked to the Drift Protocol exploit on April 1, has now drained over $575 million from DeFi in 18 days through two distinct attack vectors, highlighting the group's rapid adaptation of its tactics.