LayerZero Attributes $290 Million Kelp DAO Exploit to Inadequate Security Setup and North Korea's Lazarus Group
LayerZero has attributed the $290 million exploit of Kelp DAO to the protocol's own security configuration, stating that it had warned against the use of a single-verifier setup. The attack, which LayerZero believes with preliminary confidence was carried out by North Korea's Lazarus Group, involved compromising two remote procedure call (RPC) nodes used by LayerZero's verifier to confirm cross-chain transactions. The attackers replaced the binary software on these nodes with malicious versions that reported fraudulent transactions to LayerZero's verifier while providing accurate data to other systems. To prevent detection, the attackers also launched a distributed denial-of-service (DDoS) attack on other external RPC nodes, forcing failover to the compromised nodes. Once the failover was triggered, the compromised nodes informed the verifier that a valid cross-chain message had been received, resulting in the release of 116,500 rsETH to the attackers. The attack was only successful due to Kelp's use of a 1-of-1 verifier configuration, which meant that LayerZero Labs was the sole entity verifying messages to and from the rsETH bridge. LayerZero had recommended a multi-verifier setup with redundancy, which would have required consensus across several independent verifiers to confirm a message, thereby preventing the attack. The company has confirmed that there was no contagion to any other application on the protocol and that every OFT-standard token and application using multi-verifier setups was unaffected. The LayerZero Labs verifier is now back online, and the company will no longer sign messages for applications using single-verifier configurations, prompting a protocol-wide migration to multi-verifier setups. This distinction is significant for how DeFi prices LayerZero risk going forward, as a protocol-level bug would have implied that every OFT token on every chain was potentially at risk. However, the fact that the attack was the result of a configuration failure by a single integrator, combined with a targeted infrastructure attack, suggests that the protocol functioned as designed and that Kelp's security choices, rather than LayerZero's code, created the vulnerability. Kelp has yet to publicly respond to LayerZero's account of the incident or explain why it operated a 1-of-1 verifier setup despite explicit warnings against it. The Lazarus Group, which has been linked to the Drift Protocol exploit on April 1 and the Kelp exploit on April 18, has drained over $575 million from DeFi in 18 days using two distinct attack vectors: social engineering governance signers at Drift and poisoning infrastructure RPCs at Kelp. This demonstrates that the group is adapting its tactics faster than DeFi protocols are reinforcing their defenses.