LayerZero Attributes $290 Million Kelp Exploit to Inadequate Security Setup and North Korea's Lazarus Group
LayerZero has attributed the $290 million exploit of Kelp DAO to the protocol's own security configuration, specifically its use of a single-verifier setup despite recommendations for a multi-verifier approach. The attackers, believed to be associated with North Korea's Lazarus Group, compromised two RPC nodes that LayerZero's verifier relied on, using a novel attack vector targeting the infrastructure layer. By swapping the binary software on these nodes with malicious versions, the attackers could deceive LayerZero's verifier into confirming a fraudulent transaction while maintaining accurate data for other systems. A distributed denial-of-service attack on uncompromised external RPC nodes forced failover to the compromised nodes, allowing the attackers to release 116,500 rsETH. LayerZero emphasizes that the attack's success was dependent on Kelp's 1-of-1 verifier configuration, which ignored recommendations for redundancy. The company has confirmed no contagion to other applications and has resumed operations, announcing it will no longer support single-verifier setups.