LayerZero Points to Kelp's Security Setup as Cause of $290 Million Exploit, Links Attack to North Korea's Lazarus Group
LayerZero has attributed the $290 million exploit of Kelp DAO to a security configuration flaw on Kelp's part, stating that the protocol's single-verifier setup, contrary to LayerZero's recommendations, was the vulnerability that the attackers exploited. The novel attack vector targeted the infrastructure rather than the protocol's code. Preliminary findings suggest that North Korea's Lazarus Group and its TraderTraitor subunit were behind the attack, which involved compromising two RPC nodes that LayerZero's verifier relied on for cross-chain transaction validation. These nodes were manipulated to report false transaction data to LayerZero's verifier while maintaining accurate data for other systems. To ensure the attack remained undetected by LayerZero's monitoring, which uses different IP addresses to query the RPCs, the attackers conducted a distributed denial-of-service (DDoS) attack on the uncompromised external RPC nodes, forcing a failover to the compromised ones. Logs indicate the DDoS occurred between 10:20 a.m. and 11:40 a.m. Pacific Time on Saturday, resulting in the release of 116,500 rsETH to the attackers after the compromised nodes validated a fraudulent cross-chain message. The attack's success was contingent upon Kelp's use of a 1-of-1 verifier configuration, contrary to LayerZero's advice for a multi-verifier setup that would have required consensus across several verifiers to confirm a message, thereby preventing the attack. LayerZero has confirmed that no other applications on the protocol were affected, thanks to their use of multi-verifier setups. The LayerZero Labs verifier is now back online, with the company announcing it will no longer support applications with single-verifier configurations, prompting a protocol-wide shift away from such setups. This distinction is crucial for how DeFi assesses LayerZero's risk, as the exploit resulted from a configuration failure and targeted infrastructure attack rather than a protocol-level bug. Kelp has yet to publicly address LayerZero's account of the exploit or its decision to use a single-verifier setup despite recommendations to the contrary. The Lazarus Group, linked to the Drift Protocol exploit on April 1, has now been implicated in the Kelp exploit on April 18, indicating the group has drained over $575 million from DeFi in 18 days through distinct attack vectors, highlighting its rapid adaptation of tactics.