LayerZero Attributes $290 Million Kelp Exploit to Inadequate Security Setup and North Korea's Lazarus Group
LayerZero has identified Kelp's single-verifier configuration as the primary cause of the $290 million exploit, stating that this setup, contrary to their recommendations, allowed attackers to compromise two RPC nodes and execute a DDoS attack on others, leading to the fraudulent release of 116,500 rsETH. The attackers, believed to be from North Korea's Lazarus Group, exploited this vulnerability by swapping the binary software on the compromised nodes with malicious versions, which reported false data to LayerZero's verifier while maintaining accurate data for other systems. This selective manipulation remained undetected by LayerZero's monitoring infrastructure due to the attackers' ability to target specific nodes. The success of the attack was contingent upon Kelp's use of a 1-of-1 verifier configuration, which LayerZero had advised against in favor of a multi-verifier setup that would require consensus across several independent verifiers to confirm a message. LayerZero has confirmed that no other applications on the protocol were affected and has since taken steps to prevent similar incidents, including refusing to sign messages for applications with single-verifier setups. The incident highlights the importance of robust security configurations and the evolving threat landscape in DeFi, with Lazarus Group linked to over $575 million in losses from two exploits in less than three weeks.