LayerZero Points to Kelp's Security Setup as Cause of $290 Million Exploit, Links Attack to North Korea's Lazarus Group

LayerZero has attributed the $290 million exploit of Kelp DAO to a security vulnerability stemming from Kelp's use of a single-verifier setup, a configuration that LayerZero had explicitly warned against. The attackers, believed with preliminary confidence to be associated with North Korea's Lazarus Group and its TraderTraitor subunit, successfully compromised two remote procedure call (RPC) nodes that LayerZero's verifier relied on for cross-chain transaction validation. By swapping the binary software on these nodes with malicious versions, the attackers were able to deceive LayerZero's verifier into confirming a fraudulent transaction while maintaining the illusion of normal operations for other systems. To ensure the success of the attack, the perpetrators also launched a distributed denial-of-service (DDoS) attack on uncompromised external RPC nodes, forcing a failover to the compromised nodes. This sophisticated attack was only possible due to Kelp's single-verifier configuration, as a multi-verifier setup with redundancy, as recommended by LayerZero, would have required consensus across multiple independent verifiers to confirm a message, thereby preventing the attack. LayerZero has confirmed that there was no contagion to other applications on the protocol and has since brought its verifier back online, with the condition that it will no longer support applications running single-verifier configurations. This incident highlights the importance of security configurations and the evolving threat landscape in DeFi, with Lazarus Group linked to over $575 million in losses from DeFi exploits in just 18 days.