LayerZero Points to Kelp's Security Setup as Cause of $290 Million Exploit, Links Attack to North Korea's Lazarus Group

LayerZero has attributed the $290 million Kelp DAO exploit to Kelp's own security configuration, stating that the protocol's single-verifier setup, which LayerZero had warned against, was to blame. The attack, believed to be the work of North Korea's Lazarus Group, utilized a novel approach targeting the infrastructure rather than protocol code. By compromising two RPC nodes that LayerZero's verifier relied on, the attackers were able to deceive the verifier into confirming a fraudulent transaction. This was achieved by swapping the binary software on the compromised nodes with malicious versions, designed to provide false information to LayerZero's verifier while maintaining accurate data for other systems. To ensure the attack remained undetected by LayerZero's monitoring infrastructure, the attackers launched a distributed denial-of-service attack on uncompromised external RPC nodes, forcing a failover to the compromised ones. The attack's success was contingent upon Kelp's 1-of-1 verifier configuration, which allowed the compromised nodes to release 116,500 rsETH to the attackers. LayerZero had previously recommended a multi-verifier setup with redundancy, which would have required consensus across several independent verifiers to confirm a message, thereby preventing the attack. The company has confirmed that there was no contagion to other applications on the protocol and has since brought its verifier back online, announcing that it will no longer support applications with single-verifier configurations.