LayerZero Attributes $290 Million Kelp Exploit to Configuration Flaw and North Korean Hackers
LayerZero has assigned blame for the $290 million Kelp DAO breach to Kelp's security setup, stating that the protocol's single-verifier configuration, despite previous warnings, allowed the attack to occur. The breach utilized a novel attack vector targeting the infrastructure layer. Preliminary findings suggest the involvement of North Korea's Lazarus Group and its TraderTraitor subunit. The attackers compromised two RPC nodes used by LayerZero's verifier, then launched a DDoS attack on other nodes to force failover to the compromised ones. This resulted in the release of 116,500 rsETH to the attackers. LayerZero emphasizes that the attack's success was due to Kelp's 1-of-1 verifier configuration, contrary to recommendations for a multi-verifier setup. The company confirms no contagion to other applications and will no longer support single-verifier configurations, prompting a protocol-wide migration to more secure setups. This distinction is crucial for assessing LayerZero's risk profile, as the breach resulted from a configuration failure rather than a protocol-level bug. The Lazarus Group has been linked to two significant DeFi breaches in 18 days, totaling over $575 million, demonstrating the group's rapid adaptation of attack strategies.