LayerZero Points to Kelp's Security Setup as Cause of $290 Million Exploit, Links Attack to North Korea's Lazarus Group
LayerZero has attributed the $290 million Kelp DAO exploit to Kelp's own security configuration, stating that the protocol's single-verifier setup, which LayerZero had warned against, was the primary cause of the breach. The novel attack vector targeted the infrastructure layer, rather than the protocol code itself. According to LayerZero, the attackers, who are believed with preliminary confidence to be associated with North Korea's Lazarus Group and its TraderTraitor subunit, compromised two RPC nodes used by LayerZero's verifier to confirm cross-chain transactions. The attackers then replaced the binary software on these nodes with malicious versions designed to deceive LayerZero's verifier into accepting a fraudulent transaction, while continuing to provide accurate data to other systems querying the same nodes. To prevent detection, the attackers launched a distributed denial-of-service attack on the uncompromised external RPC nodes, forcing a failover to the compromised nodes. Once the failover occurred, the compromised nodes informed the verifier that a valid cross-chain message had been received, resulting in the release of 116,500 rsETH to the attackers. The attack was only successful due to Kelp's use of a 1-of-1 verifier configuration, which meant that LayerZero Labs was the sole entity verifying messages to and from the rsETH bridge. LayerZero had previously recommended a multi-verifier setup with redundancy, which would have required consensus across several independent verifiers to confirm a message, thereby preventing the attack. The company has confirmed that there was no contagion to any other application on the protocol and that every OFT-standard token and application running multi-verifier setups was unaffected. The LayerZero Labs verifier is now back online, and the company will no longer sign messages for applications running a 1-of-1 configuration, effectively forcing a protocol-wide migration to multi-verifier setups. The distinction between a protocol-level bug and a configuration failure is significant, as it implies that the protocol functioned as designed, and the vulnerability was created by Kelp's security choices, rather than a flaw in LayerZero's code. Kelp has yet to publicly respond to LayerZero's claims or address why it operated a 1-of-1 verifier setup despite the recommendations against it. The Lazarus Group has been linked to two major exploits in 18 days, including the Drift Protocol exploit on April 1 and the Kelp exploit on April 18, resulting in the drainage of over $575 million from DeFi through two distinct attack vectors.