LayerZero Attributes $290 Million Kelp Exploit to Poor Security Setup, Links Attack to North Korea's Lazarus Group
LayerZero has shifted the blame for the $290 million Kelp DAO exploit to Kelp's own security setup, stating that the protocol's single-verifier configuration made it vulnerable to attack. According to LayerZero, the attackers, who are believed to be from North Korea's Lazarus Group, compromised two RPC nodes that LayerZero's verifier relied on, and then launched a DDoS attack on other nodes to force a failover to the compromised ones. The attack was successful due to Kelp's failure to implement a multi-verifier setup, which would have required consensus across several independent verifiers to confirm a message. LayerZero had previously recommended this setup to Kelp, but it was ignored. The company has confirmed that there was no contagion to other applications on the protocol and that every OFT-standard token and application running multi-verifier setups was unaffected. The LayerZero Labs verifier is now back online, and the company will no longer sign messages for applications running single-verifier configurations, effectively forcing a protocol-wide migration to multi-verifier setups. This distinction is important for how DeFi prices LayerZero risk going forward, as a protocol-level bug would have implied that every OFT token on every chain was potentially at risk, whereas a configuration failure by a single integrator, combined with a targeted infrastructure attack, suggests that the protocol worked as designed and that Kelp's security choices created the vulnerability. The Lazarus Group has been linked to two major exploits in the past 18 days, including the Drift Protocol exploit on April 1, and has drained over $575 million from DeFi protocols during this time.