LayerZero Attributes $290 Million Kelp DAO Exploit to Inadequate Security Setup and Lazarus Group
LayerZero has attributed the $290 million exploit of Kelp DAO to the protocol's own security configuration, stating that the use of a single-verifier setup made it vulnerable to attack. The company had previously warned Kelp about the risks of this setup. The attack, which LayerZero believes with preliminary confidence was carried out by North Korea's Lazarus Group, involved the compromise of two remote procedure call (RPC) nodes that LayerZero's verifier relied on. These nodes were manipulated to provide false information to LayerZero's verifier while continuing to provide accurate data to other systems. To ensure the attack went undetected, the perpetrators also launched a distributed denial-of-service (DDoS) attack on uncompromised external RPC nodes, forcing a failover to the compromised nodes. Once the failover was triggered, the compromised nodes informed the verifier that a valid cross-chain message had been received, resulting in the release of 116,500 rsETH to the attackers. The malicious software then self-destructed, deleting binaries and local logs. LayerZero emphasizes that the attack was only successful because Kelp used a 1-of-1 verifier configuration, contrary to the company's recommendations for a multi-verifier setup with redundancy. This configuration would have required consensus across several independent verifiers to confirm a message, making it more difficult for the attackers to forge a valid message. LayerZero has confirmed that there was no contagion to other applications on the protocol and has resumed operations, stating that it will no longer sign messages for applications using a 1-of-1 configuration. The company's assessment of the incident highlights the importance of proper security configurations and the distinction between protocol-level bugs and configuration failures.