LayerZero Attributes $290 Million Exploit to Kelp's Security Setup and North Korea's Lazarus Group
LayerZero has attributed the $290 million Kelp DAO exploit to Kelp's own security configuration, stating that the protocol's single-verifier setup, which LayerZero had warned against, was the primary cause of the vulnerability. The attack, which LayerZero believes with preliminary confidence was carried out by North Korea's Lazarus Group, involved compromising two remote procedure call (RPC) nodes that LayerZero's verifier relied on for cross-chain transactions. By swapping the binary software on these nodes with malicious versions, the attackers were able to deceive LayerZero's verifier into confirming a fraudulent transaction while maintaining accurate data for other systems. To ensure the attack went undetected, the attackers also launched a distributed denial-of-service (DDoS) attack on uncompromised external RPC nodes, forcing a failover to the compromised nodes. This sophisticated attack was only successful due to Kelp's 1-of-1 verifier configuration, which meant that LayerZero Labs was the sole entity verifying messages to and from the rsETH bridge. Despite LayerZero's recommendations for a multi-verifier setup with redundancy, Kelp had chosen to operate with a single verifier, making it vulnerable to such an attack. The attack resulted in the release of 116,500 rsETH to the attackers, but LayerZero has confirmed that there was no contagion to other applications on the protocol. In response, LayerZero Labs will no longer sign messages for applications running 1-of-1 configurations, effectively forcing a protocol-wide migration to multi-verifier setups. This distinction is crucial for how DeFi prices LayerZero risk, as it implies that the protocol functioned as designed and that Kelp's security choices, rather than LayerZero's code, created the vulnerability. The Lazarus Group, linked to the recent Drift Protocol exploit, has now drained over $575 million from DeFi in just 18 days through two distinct attack vectors, highlighting the group's ability to adapt its playbook faster than DeFi protocols can strengthen their defenses.