LayerZero Attributes $290 Million Exploit to Kelp's Security Setup and North Korea's Lazarus Group
LayerZero has attributed the $290 million Kelp DAO exploit to Kelp's own security configuration, stating that the protocol's single-verifier setup, which LayerZero had warned against, was the primary factor in the attack's success. The attackers, believed to be from North Korea's Lazarus Group, compromised two of LayerZero's verifier's RPC nodes, using a novel attack vector targeting the infrastructure layer rather than protocol code. By swapping the binary software on these nodes with malicious versions, the attackers were able to deceive LayerZero's verifier into confirming a fraudulent transaction, while maintaining accurate data for other systems. To ensure the success of the attack, the perpetrators also launched a distributed denial-of-service attack on uncompromised external RPC nodes, forcing a failover to the compromised nodes. LayerZero emphasizes that the attack was only possible due to Kelp's 1-of-1 verifier configuration and notes that a multi-verifier setup with redundancy would have prevented the exploit. The company has confirmed no contagion to other applications on the protocol and has announced that it will no longer support single-verifier configurations, prompting a protocol-wide migration to more secure setups.