LayerZero Attributes $290 Million Kelp DAO Exploit to Inadequate Security Setup, Links Attack to North Korea's Lazarus Group
LayerZero has identified Kelp's security configuration as the primary factor behind the $290 million exploit, emphasizing that the protocol had been advised against a single-verifier setup. The attack, attributed to North Korea's Lazarus Group, involved the compromise of two RPC nodes used by LayerZero's verifier to confirm cross-chain transactions. These nodes were manipulated to report false data to LayerZero's verifier while maintaining accurate data for other systems. To ensure the attack's success, the perpetrators also initiated a DDoS attack on uncompromised external RPC nodes, forcing a failover to the compromised nodes. This sophisticated attack was only possible due to Kelp's decision to operate a 1-of-1 verifier configuration, despite recommendations for a multi-verifier setup with redundancy. LayerZero has confirmed that the attack did not affect any other applications on the protocol and has since taken measures to prevent similar incidents, including refusing to sign messages for applications with single-verifier configurations. The exploit highlights the importance of robust security measures and the need for DeFi protocols to adapt quickly to emerging threats, as the same North Korean unit has been linked to another significant exploit just 18 days prior.