LayerZero Attributes $290 Million Exploit to Kelp's Security Setup and North Korea's Lazarus Group
LayerZero has attributed the $290 million Kelp DAO exploit to Kelp's own security configuration, specifically the use of a single-verifier setup that the company had warned against. The attack, which LayerZero believes with preliminary confidence was carried out by North Korea's Lazarus Group and its TraderTraitor subunit, involved the compromise of two remote procedure call (RPC) nodes that LayerZero's verifier relied on for cross-chain transactions. The attackers replaced the legitimate software on these nodes with malicious versions that reported fraudulent transactions to LayerZero's verifier while maintaining accurate data for other systems. To ensure the attack went undetected, the attackers also launched a distributed denial-of-service (DDoS) attack on other external RPC nodes, forcing LayerZero's verifier to failover to the compromised nodes. The DDoS attack, which occurred between 10:20 a.m. and 11:40 a.m. Pacific Time on Saturday, allowed the compromised nodes to convince the verifier that a valid cross-chain message had been received, resulting in the release of 116,500 rsETH to the attackers. The malicious software then self-destructed, erasing binaries and local logs. LayerZero emphasizes that the attack was only successful because Kelp used a 1-of-1 verifier configuration, contrary to the company's recommendations for a multi-verifier setup with redundancy. Such a setup would have required consensus across multiple independent verifiers to confirm a message, making it more difficult for the attackers to forge a valid message. LayerZero has confirmed that there was no contagion to other applications on the protocol and has since brought its verifier back online, announcing that it will no longer support applications with single-verifier configurations. The distinction between a protocol-level bug and a configuration failure is significant, as it suggests that the protocol functioned as intended, and the vulnerability was the result of Kelp's security choices rather than a flaw in LayerZero's code. The Lazarus Group, which has been linked to the Drift Protocol exploit on April 1, has now been implicated in the Kelp exploit, indicating that the group has adapted its tactics to drain over $575 million from DeFi in just 18 days through two distinct attack vectors.