LayerZero Attributes $290 Million Kelp Exploit to Inadequate Security Setup and North Korea's Lazarus Group

LayerZero has attributed the $290 million Kelp DAO exploit to Kelp's security configuration, specifically its use of a single-verifier setup despite previous warnings. The attackers, believed to be North Korea's Lazarus Group, compromised two RPC nodes that LayerZero's verifier relied on, allowing them to fake a fraudulent transaction. The attack was made possible by Kelp's failure to implement a multi-verifier setup, which would have required consensus across several independent verifiers to confirm a message. LayerZero's verifier used a mix of internal and external RPC nodes for redundancy, but the attackers were able to swap the binary software on two of those nodes with malicious versions. They then launched a distributed denial-of-service attack on the uncompromised external RPC nodes, forcing failover to the compromised ones. The attack resulted in the release of 116,500 rsETH to the attackers. LayerZero has confirmed that there was no contagion to other applications on the protocol and has taken steps to prevent similar attacks in the future, including refusing to sign messages for applications running single-verifier setups. The exploit has been linked to North Korea's Lazarus Group, which has been responsible for draining over $575 million from DeFi protocols in just 18 days.