LayerZero Attributes $290 Million Kelp DAO Exploit to Inadequate Security Setup and North Korea's Lazarus Group

LayerZero has attributed the $290 million exploit of Kelp DAO to the protocol's security configuration, specifically its use of a single-verifier setup despite previous warnings. The attack, which LayerZero believes with preliminary confidence was conducted by North Korea's Lazarus Group, involved the compromise of two remote procedure call (RPC) nodes that LayerZero's verifier relied on. These nodes were manipulated to report false data to LayerZero's verifier while maintaining accurate data for other systems. To ensure the attack went undetected, the perpetrators launched a distributed denial-of-service (DDoS) attack on uncompromised external RPC nodes, forcing a failover to the compromised nodes. The DDoS, which occurred between 10:20 a.m. and 11:40 a.m. Pacific Time on Saturday, allowed the attackers to release 116,500 rsETH. The attack's success was facilitated by Kelp's 1-of-1 verifier configuration, which meant LayerZero Labs was the sole entity verifying messages to and from the rsETH bridge. LayerZero had recommended a multi-verifier setup with redundancy, which would have required consensus across several independent verifiers to confirm a message, thereby preventing the attack. The company has confirmed that there was no contagion to other applications on the protocol and has since taken the LayerZero Labs verifier offline, announcing that it will no longer sign messages for applications running a 1-of-1 configuration. This incident highlights the importance of security choices and the need for DeFi protocols to harden their defenses against evolving attack vectors, such as those employed by North Korea's Lazarus Group, which has been linked to over $575 million in DeFi exploits within 18 days.