LayerZero Points to Kelp's Security Setup as Cause of $290 Million Exploit, Links Attack to North Korea's Lazarus Group
LayerZero has attributed the $290 million exploit of Kelp DAO to Kelp's own security configuration, stating that the protocol's single-verifier setup, which LayerZero had warned against, was the primary cause of the vulnerability. The attack, which LayerZero believes with preliminary confidence was carried out by North Korea's Lazarus Group and its TraderTraitor subunit, involved the compromise of two remote procedure call (RPC) nodes that LayerZero's verifier relied on. These nodes were manipulated to report false transaction data to LayerZero's verifier while continuing to provide accurate data to other systems. To ensure the attack went undetected, the perpetrators launched a distributed denial-of-service attack on uncompromised external RPC nodes, forcing LayerZero's verifier to failover to the compromised nodes. This led to the release of 116,500 rsETH to the attackers. LayerZero emphasizes that the attack was only possible due to Kelp's 1-of-1 verifier configuration and notes that its public integration checklist and direct communications had recommended a multi-verifier setup for added security. The company has confirmed that there was no contagion to other applications on the protocol and has since brought its verifier back online, announcing that it will no longer support applications with single-verifier setups. This distinction is crucial for assessing LayerZero risk, as the exploit resulted from a configuration failure and targeted infrastructure attack rather than a protocol-level bug. Lazarus Group has been linked to another recent exploit, highlighting the group's rapid adaptation of its attack strategies and the need for DeFi protocols to enhance their defenses.