LayerZero Attributes $290 Million Kelp DAO Exploit to Inadequate Security Setup and North Korea's Lazarus Group

LayerZero has identified Kelp's single-verifier configuration as the primary factor that allowed the $290 million exploit to occur, stating that the company had previously warned against this setup. The attack, which LayerZero believes with preliminary confidence was conducted by North Korea's Lazarus Group, involved the compromise of two RPC nodes that LayerZero's verifier relied on for cross-chain transactions. These nodes were manipulated to report false transaction data to LayerZero's verifier while maintaining accurate data for other systems. To ensure the attack's success, the perpetrators also launched a distributed denial-of-service attack on uncompromised external RPC nodes, forcing a failover to the compromised nodes. The attackers then used the compromised nodes to trick Kelp's bridge into releasing 116,500 rsETH. The attack's success was contingent upon Kelp's use of a 1-of-1 verifier configuration, contrary to LayerZero's recommendations for a multi-verifier setup with redundancy. LayerZero has confirmed that no other applications on the protocol were affected and has since taken steps to prevent similar incidents, including refusing to sign messages for applications with single-verifier configurations. The distinction between a protocol-level bug and a configuration failure is crucial, as it indicates that the protocol functioned as intended, and the vulnerability was a result of Kelp's security choices rather than a flaw in LayerZero's code. The Lazarus Group has been linked to another significant exploit, highlighting the group's ability to adapt its tactics and the need for DeFi protocols to enhance their security measures.