LayerZero Attributes $290 Million Exploit to Kelp's Security Setup and North Korea's Lazarus Group
LayerZero has attributed the $290 million Kelp DAO exploit to a security configuration flaw on Kelp's part, stating that the protocol's use of a single-verifier setup made it vulnerable to attack. The exploit, which LayerZero believes with preliminary confidence was carried out by North Korea's Lazarus Group and its TraderTraitor subunit, involved the compromise of two remote procedure call (RPC) nodes that LayerZero's verifier relied on. These nodes were tricked into reporting false transaction data to LayerZero's verifier while continuing to provide accurate data to other systems. To ensure the attack went undetected, the attackers launched a distributed denial-of-service (DDoS) attack on the uncompromised RPC nodes, forcing a failover to the compromised ones. The attack resulted in the release of 116,500 rsETH to the attackers. LayerZero emphasizes that the attack was only successful because Kelp had ignored recommendations to implement a multi-verifier setup, which would have required consensus across several independent verifiers to confirm a message. The company has confirmed that there was no contagion to other applications on the protocol and has since taken the LayerZero Labs verifier offline, stating it will no longer support applications with single-verifier configurations. This incident highlights the importance of security configurations in DeFi protocols and the evolving nature of attacks, with Lazarus Group linked to over $575 million in exploits in just 18 days.