LayerZero Attributes $290 Million Exploit to Kelp's Security Configuration and North Korea's Lazarus Group

LayerZero has attributed the $290 million Kelp DAO exploit to Kelp's own security setup, citing the protocol's use of a single-verifier configuration as the primary vulnerability. The attack, which LayerZero believes with preliminary confidence was carried out by North Korea's Lazarus Group and its TraderTraitor subunit, targeted the infrastructure layer rather than the protocol's code. The attackers compromised two remote procedure call (RPC) nodes that LayerZero's verifier relied on, swapping their binary software with malicious versions designed to deceive LayerZero's verifier into confirming a fraudulent transaction. To prevent detection, the attackers also launched a distributed denial-of-service attack on uncompromised external RPC nodes, forcing a failover to the compromised nodes. LayerZero's traffic logs show the DDoS occurred between 10:20 a.m. and 11:40 a.m. Pacific Time on Saturday, resulting in the release of 116,500 rsETH to the attackers. The attack was only successful because Kelp had ignored LayerZero's recommendations for a multi-verifier setup with redundancy. LayerZero has confirmed that there was no contagion to other applications on the protocol and has since brought its verifier back online, announcing that it will no longer sign messages for applications with single-verifier configurations. The incident highlights the importance of security configuration and the need for DeFi protocols to harden their defenses against evolving attack vectors.