LayerZero Attributes $290 Million Kelp DAO Exploit to Inadequate Security Setup and North Korea's Lazarus Group
LayerZero has attributed the $290 million exploit of Kelp DAO to the protocol's single-verifier configuration, which the company had previously advised against. The attack, believed to be the work of North Korea's Lazarus Group, involved compromising two remote procedure call (RPC) nodes that LayerZero's verifier relied on, and then conducting a distributed denial-of-service (DDoS) attack on other nodes to force a failover to the compromised ones. The attackers swapped the binary software on the compromised nodes with malicious versions, allowing them to deceive LayerZero's verifier into releasing 116,500 rsETH. The attack was only successful due to Kelp's 1-of-1 verifier setup, which LayerZero had recommended against in favor of a multi-verifier configuration with redundancy. LayerZero has confirmed that there was no contagion to other applications on the protocol and has since brought its verifier back online, announcing that it will no longer support single-verifier setups. The incident highlights the importance of robust security configurations and the evolving threat landscape in the DeFi space, with the Lazarus Group having drained over $575 million in just 18 days through two distinct attack vectors.