LayerZero Points to Kelp's Security Setup as Cause of $290 Million Exploit, Links Attack to North Korea's Lazarus Group
LayerZero has attributed the $290 million Kelp DAO exploit to Kelp's security configuration, stating that the protocol's single-verifier setup, which the company had warned against, was the primary cause of the vulnerability. The attack, which LayerZero believes with preliminary confidence was carried out by North Korea's Lazarus Group and its TraderTraitor subunit, involved the compromise of two remote procedure call (RPC) nodes that LayerZero's verifier relied on to validate cross-chain transactions. By replacing the binary software on these nodes with malicious versions, the attackers were able to deceive LayerZero's verifier into confirming a fraudulent transaction while maintaining the illusion of normal operation for other systems. To ensure the success of the exploit, the attackers also launched a distributed denial-of-service (DDoS) attack on uncompromised external RPC nodes, forcing a failover to the compromised nodes and ultimately resulting in the release of 116,500 rsETH to the attackers. LayerZero emphasizes that the attack was only possible due to Kelp's 1-of-1 verifier configuration, which ignored the company's recommendations for a multi-verifier setup with redundancy. This configuration would have required consensus across multiple independent verifiers to confirm a message, thereby preventing the exploit. LayerZero has confirmed that there was no contagion to other applications on the protocol and has taken steps to prevent similar attacks in the future, including refusing to sign messages for applications with single-verifier setups.