LayerZero Attributes $290 Million Kelp Exploit to North Korea's Lazarus Group, Citing Security Setup

LayerZero has attributed the $290 million Kelp DAO exploit to Kelp's own security configuration, specifically the use of a single-verifier setup despite recommendations for a multi-verifier configuration. The attack, which LayerZero believes with preliminary confidence was carried out by North Korea's Lazarus Group, involved the compromise of two remote procedure call (RPC) nodes that LayerZero's verifier relied on. These nodes were manipulated to report fraudulent transactions to LayerZero's verifier while providing accurate data to other systems, effectively hiding the attack from LayerZero's monitoring infrastructure. To ensure the attack's success, the perpetrators also launched a distributed denial-of-service (DDoS) attack on uncompromised external RPC nodes, forcing a failover to the compromised nodes. This allowed the attackers to release 116,500 rsETH. LayerZero emphasizes that the attack was only possible due to Kelp's single-verifier setup and notes that its public integration checklist and direct communications had recommended a multi-verifier configuration for enhanced security. The company has confirmed that there was no contagion to other applications on the protocol and has announced that it will no longer support single-verifier setups, prompting a protocol-wide migration to more secure configurations. The distinction between a protocol-level bug and a configuration failure is significant for how DeFi prices LayerZero risk. Meanwhile, the Lazarus Group, linked to another recent exploit, has been adapting its tactics rapidly, posing a significant challenge to DeFi protocols' defenses.