LayerZero Points to Kelp's Security Setup as Cause of $290 Million Exploit, Links Attack to North Korea's Lazarus Group
LayerZero has attributed the responsibility for the $290 million Kelp DAO exploit to Kelp's own security configuration, stating that the protocol's single-verifier setup, which LayerZero had warned against, was the primary cause of the vulnerability. The attack, which LayerZero believes with preliminary confidence was carried out by North Korea's Lazarus Group and its TraderTraitor subunit, targeted the infrastructure layer rather than the protocol code itself. The attackers compromised two RPC nodes that LayerZero's verifier relied on, swapping their binary software with malicious versions designed to deceive LayerZero's verifier into confirming a fraudulent transaction. Meanwhile, the attackers launched a distributed denial-of-service attack on the uncompromised external RPC nodes, forcing a failover to the compromised nodes. Once the failover was triggered, the compromised nodes informed the verifier that a valid cross-chain message had arrived, resulting in Kelp's bridge releasing 116,500 rsETH to the attackers. The malicious node software then self-destructed, erasing binaries and local logs. LayerZero emphasized that the attack was only successful because Kelp had ignored recommendations to implement a multi-verifier setup with redundancy, which would have required consensus across several independent verifiers to confirm a message. The company has confirmed that there was no contagion to any other application on the protocol and has stated that it will no longer sign messages for applications running single-verifier configurations, prompting a protocol-wide migration to multi-verifier setups. The distinction between a protocol-level bug and a configuration failure is significant, as it implies that the protocol functioned as designed and that Kelp's security choices, rather than LayerZero's code, created the vulnerability. The Lazarus Group has been linked to two major exploits in 18 days, draining over $575 million from DeFi protocols through structurally different attack vectors, highlighting the group's ability to adapt its tactics faster than DeFi protocols can strengthen their defenses.