LayerZero Attributes $290 Million Exploit to Kelp's Security Setup and North Korea's Lazarus Group
LayerZero has attributed the $290 million Kelp DAO exploit to Kelp's own security configuration, stating that the protocol's single-verifier setup, which LayerZero had warned against, made the attack possible. The attack, which LayerZero believes with preliminary confidence was carried out by North Korea's Lazarus Group and its TraderTraitor subunit, involved compromising two remote procedure call (RPC) nodes that LayerZero's verifier relied on. These nodes were manipulated to report false data to LayerZero's verifier while continuing to provide accurate information to other systems, rendering the attack invisible to LayerZero's monitoring infrastructure. To ensure the attack's success, the perpetrators also launched a distributed denial-of-service attack on uncompromised external RPC nodes, forcing failover to the compromised ones. This led to the release of 116,500 rsETH to the attackers. LayerZero emphasizes that the attack was only successful because Kelp used a 1-of-1 verifier configuration, contrary to recommendations for a multi-verifier setup with redundancy. The company has confirmed that there was no contagion to other applications on the protocol and has since resumed operations, announcing that it will no longer support applications with single-verifier configurations. This incident highlights the importance of security configurations in DeFi protocols and the evolving threats posed by groups like Lazarus, which have drained over $575 million from DeFi in 18 days through two distinct attack vectors.