LayerZero Attributes $290 Million Kelp DAO Exploit to Poor Security Setup and North Korea's Lazarus Group
LayerZero has pinned the blame for the $290 million Kelp DAO exploit on Kelp's security configuration, stating that the protocol's single-verifier setup, which LayerZero had previously advised against, was the primary factor in the attack's success. The attackers, believed to be affiliated with North Korea's Lazarus Group, compromised two remote procedure call (RPC) nodes that LayerZero's verifier relied on, allowing them to deceive the verifier into confirming a fraudulent transaction. This was achieved by swapping the binary software on the compromised nodes with malicious versions, which reported false data to LayerZero's verifier while maintaining accurate data for other systems. To ensure the attack remained undetected, the attackers also launched a distributed denial-of-service (DDoS) attack on the uncompromised external RPC nodes, forcing a failover to the poisoned nodes. The DDoS attack, which occurred between 10:20 a.m. and 11:40 a.m. Pacific Time on Saturday, enabled the compromised nodes to convince the verifier that a valid cross-chain message had been received, resulting in the release of 116,500 rsETH to the attackers. Following the attack, the malicious node software self-destructed, erasing binaries and local logs. LayerZero emphasized that the attack was only successful because Kelp had chosen to operate a 1-of-1 verifier configuration, ignoring recommendations for a multi-verifier setup with redundancy. This configuration would have required consensus across multiple independent verifiers to confirm a message, making it more difficult for the attackers to forge a valid message. LayerZero has confirmed that there was no contagion to other applications on the protocol and has announced that it will no longer sign messages for applications using single-verifier setups, effectively forcing a protocol-wide migration to multi-verifier configurations. The distinction between a protocol-level bug and a configuration failure is significant, as it suggests that the protocol functioned as intended, and the vulnerability was created by Kelp's security choices rather than any issues with LayerZero's code. Kelp has yet to publicly respond to LayerZero's account of the events or explain why it chose to operate a 1-of-1 verifier setup despite explicit warnings against it. The Lazarus Group, which has been linked to the Drift Protocol exploit on April 1, has now been implicated in the Kelp exploit, marking the second major attack by the group in just 18 days, with total losses exceeding $575 million. This highlights the group's ability to adapt its tactics faster than DeFi protocols can strengthen their defenses.