LayerZero Attributes $290 Million Kelp Exploit to North Korea's Lazarus Group, Citing Poor Security Setup

LayerZero has attributed the $290 million Kelp DAO exploit to Kelp's own security configuration, stating that the protocol's single-verifier setup, which the company had previously warned against, was the primary cause of the vulnerability. The attack, which LayerZero believes with preliminary confidence was carried out by North Korea's Lazarus Group, involved the compromise of two remote procedure call (RPC) nodes that LayerZero's verifier relied on to confirm cross-chain transactions. These nodes were manipulated to report fraudulent transactions to LayerZero's verifier while maintaining accurate data for other systems. To ensure the attack's success, the perpetrators also launched a distributed denial-of-service attack on uncompromised external RPC nodes, forcing failover to the compromised nodes. The attack resulted in the release of 116,500 rsETH to the attackers. LayerZero emphasizes that the exploit was only possible due to Kelp's 1-of-1 verifier configuration and notes that its public integration checklist and direct communications had recommended a multi-verifier setup with redundancy. The company has confirmed that there was no contagion to other applications on the protocol and has announced that it will no longer support single-verifier configurations, prompting a protocol-wide migration to multi-verifier setups. This incident highlights the importance of security configurations and the evolving nature of attacks, with the Lazarus Group having drained over $575 million from DeFi in 18 days through two distinct attack vectors.