LayerZero Attributes $290 Million Kelp Exploit to Inadequate Security Setup and North Korea's Lazarus Group
LayerZero has attributed the $290 million Kelp DAO exploit to Kelp's security configuration, specifically the use of a single-verifier setup despite recommendations for a multi-verifier approach. The attack, believed to be the work of North Korea's Lazarus Group, involved the compromise of two RPC nodes used by LayerZero's verifier, which were then used to deceive the verifier into accepting a fraudulent transaction. This was achieved by swapping the binary software on the compromised nodes with malicious versions that reported false data to LayerZero's verifier while continuing to provide accurate data to other systems. To ensure the attack remained undetected, the attackers also launched a distributed denial-of-service attack on other RPC nodes, forcing a failover to the compromised nodes. Once the failover was triggered, the compromised nodes informed the verifier that a valid cross-chain message had been received, resulting in the release of 116,500 rsETH to the attackers. The malicious software then self-destructed, eliminating any local logs or binaries. LayerZero emphasizes that the attack's success was directly due to Kelp's 1-of-1 verifier configuration, which meant that only one entity was responsible for verifying messages to and from the rsETH bridge. In contrast, a multi-verifier setup with redundancy, where consensus across several independent verifiers is required to confirm a message, would have prevented the attack. LayerZero had previously recommended such a setup to Kelp. The company has confirmed that there was no contagion to other applications on the protocol, with all OFT-standard tokens and applications using multi-verifier setups remaining unaffected. In response to the incident, LayerZero Labs' verifier is now back online, and the company will no longer support applications with single-verifier configurations, effectively mandating a protocol-wide shift away from such setups. This distinction is crucial for how DeFi assesses LayerZero risk, as it differentiates between a protocol-level bug, which would imply a broader risk, and a configuration failure by a single integrator combined with a targeted infrastructure attack, indicating that the protocol functioned as intended and the vulnerability was due to Kelp's security choices, not LayerZero's code. The Lazarus Group, linked to the recent Drift Protocol exploit, has now been implicated in draining over $575 million from DeFi in just 18 days through two distinct attack vectors, highlighting the group's ability to adapt its tactics faster than DeFi protocols can enhance their defenses.