LayerZero Attributes $290 Million Kelp Exploit to Security Setup and North Korea's Lazarus Group

LayerZero has attributed the $290 million exploit of Kelp DAO to the protocol's security configuration, stating that Kelp's use of a single-verifier setup, despite recommendations for a multi-verifier setup, was the primary factor. The attack, which LayerZero believes with preliminary confidence was carried out by North Korea's Lazarus Group and its TraderTraitor subunit, involved the compromise of two remote procedure call (RPC) nodes that LayerZero's verifier relied on. These nodes were manipulated to report false transaction data to LayerZero's verifier while continuing to provide accurate data to other systems. To ensure the attack remained undetected by LayerZero's monitoring infrastructure, the attackers launched a distributed denial-of-service (DDoS) attack on uncompromised external RPC nodes, forcing failover to the compromised nodes. The DDoS, which occurred between 10:20 a.m. and 11:40 a.m. Pacific Time on Saturday, allowed the attackers to release 116,500 rsETH. The malicious software then self-destructed, removing any traces of the attack. LayerZero emphasizes that the attack's success was contingent upon Kelp's single-verifier configuration, which allowed the compromised nodes to forge a valid cross-chain message. In contrast, a multi-verifier setup with redundancy, as recommended by LayerZero, would have required consensus across several independent verifiers, thereby preventing the attack. LayerZero has confirmed that there was no contagion to other applications on the protocol and has since taken the LayerZero Labs verifier offline, announcing that it will no longer support applications with single-verifier setups. The distinction between a protocol-level bug and a configuration failure is significant, as it implies that the protocol functioned as intended, and the vulnerability was a result of Kelp's security choices rather than a flaw in LayerZero's code. The Lazarus Group has been linked to two major exploits in 18 days, including the Drift Protocol exploit on April 1, resulting in over $575 million drained from DeFi protocols through distinct attack vectors.