LayerZero Attributes $290 Million Kelp Exploit to Inadequate Security Setup, Points to North Korea's Lazarus Group

LayerZero has attributed the $290 million exploit of Kelp DAO to the protocol's single-verifier security configuration, which the company had warned against. The attack, linked to North Korea's Lazarus Group, involved compromising two RPC nodes that LayerZero's verifier relied on and conducting a DDoS attack on other nodes to force failover to the compromised ones. This novel attack vector, targeting the infrastructure layer rather than protocol code, was only possible because Kelp had ignored recommendations for a multi-verifier setup. LayerZero's verifier used a mix of internal and external RPC nodes for redundancy, but the attackers managed to swap the binary software on two nodes with malicious versions, which reported fraudulent transactions to LayerZero's verifier while providing accurate data to other systems. The attackers then conducted a DDoS attack on uncompromised external RPC nodes, forcing failover to the poisoned ones and resulting in the release of 116,500 rsETH to the attackers. The attack was only successful because Kelp ran a 1-of-1 verifier configuration, and LayerZero had recommended a multi-verifier setup with redundancy. The company has confirmed no contagion to other applications on the protocol and has taken the LayerZero Labs verifier offline, refusing to sign messages for applications running single-verifier configurations. This distinction is crucial for how DeFi prices LayerZero risk, as the exploit was a result of Kelp's security choices rather than a protocol-level bug. The Lazarus Group has been linked to two major exploits in 18 days, draining over $575 million from DeFi through structurally different attack vectors, highlighting the need for DeFi protocols to harden their defenses against evolving threats.