LayerZero Points to Kelp's Security Setup as Cause of $290 Million Exploit, Links Attack to North Korea's Lazarus Group

LayerZero has attributed the $290 million exploit of Kelp DAO to Kelp's own security configuration, specifically the use of a single-verifier setup despite previous warnings against it. The attack, which LayerZero believes with preliminary confidence was carried out by North Korea's Lazarus Group, involved compromising two remote procedure call (RPC) nodes that LayerZero's verifier relied on. These nodes were manipulated to report fraudulent transactions to LayerZero's verifier while providing accurate data to other systems, effectively hiding the attack from LayerZero's monitoring. To ensure the attack's success, the perpetrators also launched a distributed denial-of-service (DDoS) attack on uncompromised external RPC nodes, forcing a failover to the compromised nodes. The attack resulted in the release of 116,500 rsETH to the attackers. LayerZero emphasizes that the exploit was only possible due to Kelp's 1-of-1 verifier configuration and notes that its public integration checklist and direct communications had recommended a multi-verifier setup for enhanced security. The company has confirmed that there was no contagion to other applications on the protocol and has since brought its verifier back online, announcing that it will no longer support applications with single-verifier setups. This incident highlights the importance of security configurations in DeFi and the evolving tactics of attackers like the Lazarus Group, which has been linked to significant exploits in the space.