LayerZero Attributes $290 Million Kelp Exploit to Inadequate Security Setup, Links Attack to North Korea's Lazarus Group
LayerZero has attributed the recent $290 million exploit of Kelp DAO to a security vulnerability resulting from Kelp's use of a single-verifier setup, a configuration that LayerZero had previously advised against. The attack, which LayerZero believes with preliminary confidence was conducted by North Korea's Lazarus Group, involved a novel approach targeting the infrastructure layer rather than exploiting any vulnerabilities in the protocol's code. The attackers compromised two remote procedure call (RPC) nodes that LayerZero's verifier depended on to validate cross-chain transactions, and then launched a distributed denial-of-service (DDoS) attack on the remaining uncompromised nodes to force a failover to the malicious nodes. This selective manipulation allowed the attackers to deceive LayerZero's verifier into confirming a fraudulent transaction without being detected by LayerZero's monitoring infrastructure, which queries the RPC nodes from different IP addresses. The attack's success was contingent upon Kelp's 1-of-1 verifier configuration, where LayerZero Labs was the sole entity verifying messages to and from the rsETH bridge. LayerZero had explicitly recommended a multi-verifier setup with redundancy to Kelp, which would have required consensus across multiple independent verifiers to confirm a message, thereby preventing the attack. Following the incident, LayerZero confirmed that there was no contagion to any other application on the protocol, with all OFT-standard tokens and applications running multi-verifier setups remaining unaffected. The LayerZero Labs verifier is now back online, and the company has announced that it will no longer support applications with single-verifier configurations, prompting a protocol-wide migration to more secure multi-verifier setups. This distinction is crucial for how DeFi assesses LayerZero risk going forward, as the exploit resulted from a configuration failure by a single integrator combined with a targeted infrastructure attack, rather than a protocol-level bug. The attack has been linked to the Lazarus Group, which has been implicated in the Drift Protocol exploit on April 1, resulting in the loss of over $575 million from DeFi in just 18 days through two distinct attack vectors.