LayerZero Attributes $290 Million Exploit to Kelp's Security Setup and North Korea's Lazarus Group
LayerZero has attributed the $290 million Kelp DAO exploit to Kelp's security configuration, stating that the protocol's single-verifier setup, which LayerZero had previously advised against, was the primary cause of the vulnerability. The attack, which LayerZero believes with preliminary confidence was carried out by North Korea's Lazarus Group, involved the compromise of two remote procedure call (RPC) nodes that LayerZero's verifier relied on for cross-chain transactions. These nodes were manipulated to report false data to LayerZero's verifier while maintaining accurate data for other systems, effectively hiding the attack from LayerZero's monitoring infrastructure. The attackers also launched a distributed denial-of-service (DDoS) attack on uncompromised external RPC nodes to force failover to the compromised nodes, resulting in the release of 116,500 rsETH to the attackers. LayerZero emphasizes that the attack was only successful due to Kelp's single-verifier configuration, which ignored recommendations for a multi-verifier setup with redundancy. The company has confirmed no contagion to other applications on the protocol and has resumed operations with the LayerZero Labs verifier, but will no longer support applications with single-verifier configurations. This distinction is crucial for DeFi's risk assessment of LayerZero going forward, as the exploit was the result of a configuration failure by Kelp rather than a protocol-level bug in LayerZero's code.