LayerZero Attributes $290 Million Kelp DAO Exploit to Inadequate Security Setup and North Korea's Lazarus Group
LayerZero has attributed the $290 million exploit of Kelp DAO to the protocol's single-verifier security configuration, which the company had previously advised against. The attack, believed to be the work of North Korea's Lazarus Group, involved the compromise of two remote procedure call (RPC) nodes relied upon by LayerZero's verifier. These nodes were manipulated to report false transaction data to LayerZero's verifier while maintaining accurate data for other systems. To ensure the attack's success, the perpetrators also launched a distributed denial-of-service (DDoS) attack on uncompromised external RPC nodes, forcing a failover to the compromised nodes. This sophisticated attack was only possible due to Kelp's failure to implement a multi-verifier setup, a configuration that LayerZero had recommended to enhance security. The attack resulted in the release of 116,500 rsETH to the attackers. LayerZero has confirmed that the attack did not affect any other applications on the protocol and has since taken steps to prevent similar incidents, including refusing to sign messages for applications with single-verifier configurations. The incident highlights the importance of robust security measures and the need for DeFi protocols to strengthen their defenses against evolving threats.