LayerZero Attributes $290 Million Kelp Exploit to Inadequate Security Setup, Points to Lazarus Group

LayerZero has shifted the blame for the $290 million Kelp DAO exploit to Kelp's security setup, stating that the protocol's single-verifier configuration, which LayerZero had warned against, was the primary cause of the breach. The attack, attributed to North Korea's Lazarus Group with preliminary confidence, involved compromising two remote procedure call (RPC) nodes that LayerZero's verifier relied on for cross-chain transactions. The attackers replaced the binary software on these nodes with malicious versions, which reported fraudulent transactions to LayerZero's verifier while providing accurate data to other systems. To prevent detection, the attackers launched a distributed denial-of-service attack on uncompromised external RPC nodes, forcing failover to the compromised nodes. LayerZero's traffic logs show the DDoS occurred between 10:20 a.m. and 11:40 a.m. Pacific Time on Saturday, resulting in the release of 116,500 rsETH to the attackers. The company emphasizes that the attack was only successful due to Kelp's 1-of-1 verifier configuration and notes that a multi-verifier setup with redundancy, as recommended, would have prevented the breach. LayerZero has confirmed no contagion to other applications on the protocol and has resumed operations, announcing that it will no longer support single-verifier configurations. The incident highlights the importance of security configurations in DeFi and the evolving nature of attacks, with the Lazarus Group linked to over $575 million in DeFi losses in just 18 days.