LayerZero Attributes $290 Million Kelp Exploit to Inadequate Security Setup and North Korea's Lazarus Group

LayerZero has attributed the $290 million exploit of Kelp DAO to the protocol's single-verifier security configuration, which the company had previously advised against. The attack, which LayerZero believes with preliminary confidence was carried out by North Korea's Lazarus Group, involved compromising two remote procedure call (RPC) nodes that LayerZero's verifier relied on for cross-chain transactions. These nodes were manipulated to report false transaction data to LayerZero's verifier while maintaining accurate data for other systems. To ensure the attack went undetected, the perpetrators also launched a distributed denial-of-service (DDoS) attack on uncompromised external RPC nodes, forcing a failover to the compromised nodes. This allowed the attackers to release 116,500 rsETH. The attack's success is attributed to Kelp's use of a 1-of-1 verifier configuration, contrary to LayerZero's recommendations for a multi-verifier setup that would have required consensus across multiple verifiers to confirm transactions. LayerZero has confirmed that no other applications on the protocol were affected and has since ceased signing messages for applications with single-verifier configurations, prompting a protocol-wide migration to multi-verifier setups. This incident highlights the distinction between protocol-level bugs and configuration failures by integrators, with the latter being the case in the Kelp exploit. The Lazarus Group, linked to the Drift Protocol exploit, has now been implicated in draining over $575 million from DeFi protocols in 18 days through two distinct attack vectors.