LayerZero Attributes $290 Million Kelp Exploit to Inadequate Security Setup and North Korea's Lazarus Group

LayerZero has assigned blame for the $290 million Kelp DAO exploit to Kelp's own security configuration, stating that the protocol's single-verifier setup, which LayerZero had warned against, was the primary factor in the attack's success. The exploit was made possible by a novel attack vector targeting the infrastructure layer, rather than any protocol code. According to LayerZero, the attackers, who are believed with preliminary confidence to be part of North Korea's Lazarus Group and its TraderTraitor subunit, compromised two remote procedure call (RPC) nodes used by LayerZero's verifier to confirm cross-chain transactions. These nodes were swapped with malicious versions designed to deceive LayerZero's verifier into believing a fraudulent transaction had occurred, while providing accurate data to other systems. To maintain the attack's stealth, the compromised nodes only lied to LayerZero's verifier, which queries the RPCs from different IP addresses. However, compromising two nodes was insufficient, as LayerZero's verifier also relied on uncompromised external RPC nodes. To overcome this, the attackers launched a distributed denial-of-service attack on the uncompromised nodes, forcing a failover to the poisoned ones. The DDoS, which occurred between 10:20 a.m. and 11:40 a.m. Pacific Time on Saturday, ultimately led to the release of 116,500 rsETH to the attackers. The malicious node software then self-destructed, wiping binaries and local logs. The attack's success can be attributed to Kelp's 1-of-1 verifier configuration, which meant that LayerZero Labs was the sole entity verifying messages to and from the rsETH bridge. LayerZero had recommended a multi-verifier setup with redundancy, which would have required consensus across several independent verifiers to confirm a message, thereby preventing the attack. LayerZero has confirmed that there was no contagion to any other application on the protocol, and every OFT-standard token and application running multi-verifier setups was unaffected. The LayerZero Labs verifier is now back online, and the company will no longer sign messages for any application running a 1-of-1 configuration, prompting a protocol-wide migration off single-verifier setups. This distinction is crucial for how DeFi prices LayerZero risk going forward, as a protocol-level bug would have implied that every OFT token on every chain was potentially at risk. However, the fact that the exploit was the result of a configuration failure by a single integrator, combined with a targeted infrastructure attack, suggests that the protocol functioned as designed and that Kelp's security choices, rather than LayerZero's code, created the vulnerability. Kelp has yet to publicly respond to LayerZero's assessment or explain why it operated a 1-of-1 verifier setup despite explicit recommendations against it. The Lazarus Group has been linked to two significant exploits in 18 days, including the Drift Protocol exploit on April 1 and the Kelp exploit on April 18, resulting in the loss of over $575 million from DeFi. The group's ability to adapt its tactics faster than DeFi protocols can strengthen their defenses poses a significant challenge to the industry.