LayerZero Attributes $290 Million Exploit to Kelp's Security Setup and North Korea's Lazarus Group
LayerZero has attributed the $290 million Kelp DAO exploit to Kelp's own security configuration, stating that the protocol's single-verifier setup, which LayerZero had warned against, was the primary cause of the vulnerability. The attack, which LayerZero believes with preliminary confidence was carried out by North Korea's Lazarus Group and its TraderTraitor subunit, targeted the infrastructure layer rather than the protocol code itself. The attackers compromised two remote procedure call (RPC) nodes that LayerZero's verifier relied on, swapping their software with malicious versions designed to deceive LayerZero's verifier into confirming a fraudulent transaction. To maintain stealth, the attackers also launched a distributed denial-of-service attack on uncompromised external RPC nodes, forcing a failover to the compromised nodes. LayerZero's traffic logs show the DDoS occurred between 10:20 a.m. and 11:40 a.m. Pacific Time on Saturday, resulting in Kelp's bridge releasing 116,500 rsETH to the attackers. The attack's success was contingent upon Kelp's 1-of-1 verifier configuration, which LayerZero had recommended against in favor of a multi-verifier setup with redundancy. LayerZero has confirmed that no other applications on the protocol were affected and has announced that it will no longer support single-verifier configurations. The distinction between a protocol-level bug and a configuration failure is significant for how DeFi prices LayerZero risk going forward. The Lazarus Group has been linked to two major exploits in 18 days, draining over $575 million from DeFi through distinct attack vectors, highlighting the group's adaptability and the need for DeFi protocols to strengthen their defenses.