LayerZero Attributes $290 Million Kelp Exploit to Inadequate Security Setup and North Korea's Lazarus Group

LayerZero has attributed the $290 million exploit of Kelp DAO to the protocol's own security configuration, specifically its use of a single-verifier setup, which the company had previously advised against. The attack, which LayerZero believes with preliminary confidence was carried out by North Korea's Lazarus Group and its TraderTraitor subunit, involved compromising two remote procedure call (RPC) nodes that LayerZero's verifier relied on to validate cross-chain transactions. By swapping the software on these nodes with malicious versions, the attackers were able to deceive LayerZero's verifier into confirming a fraudulent transaction while reporting accurate data to other systems. The attackers also launched a distributed denial-of-service (DDoS) attack on uncompromised external RPC nodes to force failover to the compromised nodes. LayerZero's traffic logs show the DDoS occurred between 10:20 a.m. and 11:40 a.m. Pacific Time on Saturday, resulting in the release of 116,500 rsETH to the attackers. The attack was only successful because Kelp used a 1-of-1 verifier configuration, meaning LayerZero Labs was the sole entity verifying messages to and from the rsETH bridge. LayerZero had recommended a multi-verifier setup with redundancy, which would have required consensus across several independent verifiers to confirm a message, thereby preventing the attack. The company has confirmed that there was no contagion to any other application on the protocol and that every OFT-standard token and application running multi-verifier setups was unaffected. The LayerZero Labs verifier is now back online, and the company will no longer sign messages for applications running a 1-of-1 configuration, prompting a protocol-wide migration to multi-verifier setups. This distinction is significant for how DeFi prices LayerZero risk going forward, as a protocol-level bug would have implied that every OFT token on every chain was potentially at risk. However, the fact that the exploit resulted from a configuration failure by a single integrator, combined with a targeted infrastructure attack, suggests that the protocol functioned as designed and that Kelp's security choices, rather than LayerZero's code, created the vulnerability. Kelp has not yet publicly responded to LayerZero's account of the incident or explained why it operated a 1-of-1 verifier setup despite the recommendations against it. The Lazarus Group has been linked to two major exploits in 18 days, including the Drift Protocol exploit on April 1 and the Kelp exploit on April 18, resulting in the drainage of over $575 million from DeFi through two distinct attack vectors.