LayerZero Points to Kelp's Security Setup as Cause of $290 Million Exploit, Links Attack to North Korea's Lazarus Group
LayerZero has attributed the responsibility for the $290 million Kelp DAO exploit to Kelp's own security configuration, stating that the protocol's single-verifier setup, which the company had warned against, was the primary cause of the vulnerability. The attack, attributed to North Korea's Lazarus Group, involved a novel vector targeting the infrastructure layer rather than protocol code. The attackers compromised two RPC nodes, which are servers that allow software to read and write data on a blockchain, and swapped the binary software with malicious versions designed to deceive LayerZero's verifier into confirming a fraudulent transaction. This selective deception was engineered to remain undetected by LayerZero's monitoring infrastructure. To ensure the attack's success, the perpetrators also launched a distributed denial-of-service attack on uncompromised external RPC nodes, forcing a failover to the compromised nodes. The attack resulted in the release of 116,500 rsETH to the attackers. LayerZero emphasizes that the attack was only possible due to Kelp's 1-of-1 verifier configuration and notes that its public integration checklist and direct communications to Kelp had recommended a multi-verifier setup with redundancy. The company confirms that there has been no contagion to other applications on the protocol and that every OFT-standard token and application running multi-verifier setups was unaffected. In response, LayerZero Labs will no longer sign messages for applications running a 1-of-1 configuration, prompting a protocol-wide migration off single-verifier setups. This distinction is significant for how DeFi prices LayerZero risk going forward, as it implies that the protocol worked as designed, and Kelp's security choices, rather than LayerZero's code, created the vulnerability. The attack highlights the adaptability of the Lazarus Group, which has been linked to the Drift Protocol exploit, resulting in over $575 million drained from DeFi in 18 days through two distinct attack vectors.