LayerZero Attributes $290 Million Kelp Exploit to North Korea's Lazarus Group, Citing Security Setup
LayerZero has attributed the $290 million Kelp DAO exploit to Kelp's own security configuration, specifically its use of a single-verifier setup despite previous warnings against such a configuration. The attack, which LayerZero attributes with preliminary confidence to North Korea's Lazarus Group and its TraderTraitor subunit, exploited a novel vector targeting the infrastructure layer rather than any protocol code. The attackers compromised two remote procedure call (RPC) nodes that LayerZero's verifier relied on, swapping their binary software with malicious versions designed to deceive LayerZero's verifier into confirming fraudulent transactions while reporting accurate data to other systems. To ensure the attack's success, the attackers also launched a distributed denial-of-service (DDoS) attack on uncompromised external RPC nodes, forcing a failover to the compromised nodes. According to LayerZero, the attack only succeeded because Kelp operated a 1-of-1 verifier configuration, contrary to recommendations for a multi-verifier setup with redundancy. LayerZero has confirmed that there was no contagion to other applications on the protocol and has since taken the LayerZero Labs verifier offline, announcing that it will no longer sign messages for applications running 1-of-1 configurations. This incident highlights the importance of security configurations and the evolving tactics of threat actors like the Lazarus Group, which has been linked to over $575 million in DeFi exploits within an 18-day period.