LayerZero Attributes $290 Million Exploit to Kelp's Security Setup and North Korea's Lazarus Group
LayerZero has attributed the $290 million Kelp DAO exploit to Kelp's own security configuration, specifically the use of a single-verifier setup despite prior warnings. The attack, preliminarily linked to North Korea's Lazarus Group, exploited a novel vector targeting the infrastructure layer. The hackers compromised two RPC nodes used by LayerZero's verifier for cross-chain transactions, swapping the binary software with malicious versions. These nodes reported false data to LayerZero's verifier while maintaining accurate data for other systems. To ensure the attack went undetected, the attackers launched a DDoS attack on uncompromised external RPC nodes, forcing a failover to the compromised nodes. Once the failover occurred, the compromised nodes validated a fraudulent transaction, resulting in the release of 116,500 rsETH to the attackers. The attack's success was facilitated by Kelp's 1-of-1 verifier configuration, which LayerZero had advised against in favor of a multi-verifier setup with redundancy. LayerZero confirmed no contagion to other applications on the protocol and has since brought its verifier back online, announcing it will no longer support applications with single-verifier configurations. The distinction between a protocol-level bug and a configuration failure is significant for how DeFi prices LayerZero risk. The attack highlights the adaptability of Lazarus Group, which has drained over $575 million from DeFi in 18 days through two distinct attack vectors.