LayerZero Pins $290 Million Exploit on Kelp's Security Setup, Links Attack to North Korea's Lazarus Group
LayerZero has attributed the $290 million exploit of Kelp DAO to a security configuration issue on Kelp's part, stating that the protocol's single-verifier setup, which LayerZero had warned against, was the primary factor in the attack's success. The attack, which LayerZero believes with preliminary confidence was conducted by North Korea's Lazarus Group, involved the compromise of two remote procedure call (RPC) nodes that LayerZero's verifier relied on for cross-chain transaction verification. By swapping the binary software on these nodes with malicious versions, the attackers were able to deceive LayerZero's verifier into confirming a fraudulent transaction while maintaining the illusion of normal operation for other systems querying the same nodes. To ensure the attack remained undetected by LayerZero's monitoring infrastructure, the attackers launched a distributed denial-of-service (DDoS) attack on uncompromised external RPC nodes, forcing a failover to the compromised nodes. The DDoS, which occurred between 10:20 a.m. and 11:40 a.m. Pacific Time on Saturday, ultimately led to the release of 116,500 rsETH to the attackers. The attack's success was contingent upon Kelp's use of a 1-of-1 verifier configuration, contrary to LayerZero's recommendations for a multi-verifier setup with redundancy. Such a setup would have required consensus across multiple independent verifiers to confirm a message, thereby preventing the attack. LayerZero has confirmed that there was no contagion to other applications on the protocol and has since brought its verifier back online, announcing that it will no longer support applications with single-verifier configurations. The distinction between a protocol-level bug and a configuration failure is significant for how DeFi prices LayerZero risk. While a protocol-level bug would have implied that all OFT tokens were at risk, the fact that the exploit was the result of a targeted infrastructure attack and a single integrator's configuration failure suggests that the protocol functioned as designed. Kelp has yet to publicly address LayerZero's assertions or explain why it opted for a 1-of-1 verifier setup despite explicit warnings against it. The Lazarus Group, linked to both the Kelp and Drift Protocol exploits, has drained over $575 million from DeFi in just 18 days, demonstrating its ability to adapt its tactics faster than DeFi protocols can fortify their defenses.