LayerZero Attributes $290 Million Kelp Exploit to Security Configuration, Links Attack to North Korea's Lazarus Group

LayerZero has attributed the $290 million exploit of Kelp DAO to the protocol's security configuration, specifically its use of a single-verifier setup despite recommendations for a multi-verifier configuration. The attack, which LayerZero believes with preliminary confidence was carried out by North Korea's Lazarus Group, involved the compromise of two remote procedure call (RPC) nodes that LayerZero's verifier relied on for cross-chain transactions. The attackers replaced the binary software on these nodes with malicious versions, which reported fraudulent transactions to LayerZero's verifier while maintaining accurate data for other systems. To prevent detection, the attackers also launched a distributed denial-of-service (DDoS) attack on uncompromised external RPC nodes, forcing failover to the compromised nodes. Once the failover was triggered, the compromised nodes confirmed a valid cross-chain message, resulting in the release of 116,500 rsETH to the attackers. The attack was only successful due to Kelp's single-verifier configuration, which allowed the poisoning of a single verifier's data feed to forge a valid message. LayerZero had previously recommended a multi-verifier setup with redundancy, which would have required consensus across several independent verifiers to confirm a message. The company has confirmed that there was no contagion to other applications on the protocol and has taken steps to prevent similar attacks in the future, including refusing to sign messages for applications running single-verifier configurations. The incident highlights the importance of robust security configurations and the need for DeFi protocols to harden their defenses against increasingly sophisticated attacks.