LayerZero Attributes $290 Million Exploit to Kelp's Security Setup and North Korea's Lazarus Group

LayerZero has attributed the $290 million Kelp DAO exploit to Kelp's own security configuration, stating that the protocol's single-verifier setup, contrary to LayerZero's prior warnings and recommendations for a multi-verifier setup, was the critical vulnerability. The attack, preliminarily attributed to North Korea's Lazarus Group and its TraderTraitor subunit, involved compromising two remote procedure call (RPC) nodes that LayerZero's verifier relied on. These nodes were manipulated to report false transaction data to LayerZero's verifier while maintaining accurate data for other querying systems, thereby evading detection. To ensure the attack's success, the perpetrators launched a distributed denial-of-service (DDoS) attack on uncompromised external RPC nodes, forcing a failover to the compromised nodes. This sophisticated attack resulted in the release of 116,500 rsETH to the attackers. LayerZero emphasizes that the attack's success was contingent upon Kelp's 1-of-1 verifier configuration and notes that a multi-verifier setup, as recommended, would have prevented the exploit. The company confirms no contagion to other applications on the protocol and will no longer support single-verifier configurations, prompting a protocol-wide migration to more secure setups. This incident highlights the distinction between protocol-level vulnerabilities and configuration failures by integrators, with implications for how DeFi prices LayerZero risk. The Lazarus Group's involvement marks a concerning trend, with over $575 million drained from DeFi protocols in 18 days through diverse attack vectors, underscoring the need for enhanced defenses.