LayerZero Attributes $290 Million Kelp Exploit to Inadequate Security Setup and North Korea's Lazarus Group

LayerZero has attributed the $290 million exploit of Kelp DAO to the protocol's own security configuration, specifically its use of a single-verifier setup despite recommendations for a multi-verifier configuration. The attack, which LayerZero believes with preliminary confidence was carried out by North Korea's Lazarus Group, involved the compromise of two RPC nodes used by LayerZero's verifier to confirm cross-chain transactions. These nodes were manipulated to report false data to LayerZero's verifier while continuing to provide accurate information to other systems, effectively hiding the attack from LayerZero's monitoring infrastructure. To ensure the attack's success, the perpetrators also conducted a distributed denial-of-service attack on other external RPC nodes, forcing a failover to the compromised nodes. The attack resulted in the release of 116,500 rsETH to the attackers. LayerZero emphasizes that the exploit was only possible due to Kelp's 1-of-1 verifier configuration and notes that its public integration checklist and direct communications had recommended a multi-verifier setup for enhanced security. The company has confirmed that there was no contagion to other applications on the protocol and has since taken the LayerZero Labs verifier offline, announcing that it will no longer support applications with single-verifier configurations. This incident highlights the importance of robust security configurations in DeFi and the evolving nature of threats, with Lazarus Group linked to over $575 million in losses from DeFi exploits in just 18 days.