LayerZero Attributes $290 Million Exploit to Kelp's Security Setup and North Korea's Lazarus Group

LayerZero has attributed the $290 million Kelp DAO exploit to Kelp's own security configuration, stating that the liquid restaking protocol's single-verifier setup, despite previous warnings, allowed the attack to occur. The novel attack vector targeted the infrastructure layer rather than the protocol code itself. According to LayerZero, the attackers, believed with preliminary confidence to be North Korea's Lazarus Group and its TraderTraitor subunit, compromised two remote procedure call (RPC) nodes used by LayerZero's verifier for cross-chain transactions. These nodes, critical for reading and writing blockchain data, were manipulated to report fraudulent transactions to LayerZero's verifier while maintaining accurate data for other systems. To ensure the attack remained undetected by LayerZero's monitoring, which uses different IP addresses to query the same RPCs, the attackers conducted a distributed denial-of-service (DDoS) attack on uncompromised external RPC nodes, forcing a failover to the compromised nodes. Logs show the DDoS occurred between 10:20 a.m. and 11:40 a.m. Pacific Time on Saturday, resulting in the release of 116,500 rsETH to the attackers. The success of the attack was directly tied to Kelp's use of a 1-of-1 verifier configuration, contrary to LayerZero's recommendations for a multi-verifier setup with redundancy. Such a setup would have required consensus across multiple independent verifiers to confirm a message, thereby preventing the attack. LayerZero has confirmed no contagion to other applications on the protocol and has stated that it will no longer support applications with single-verifier configurations, prompting a protocol-wide migration to more secure setups. The distinction between a protocol-level bug and a configuration failure is significant for how DeFi assesses LayerZero's risk. Meanwhile, the Lazarus Group, linked to the recent Drift Protocol exploit, has been implicated in draining over $575 million from DeFi in just 18 days through two distinct attack vectors, highlighting the group's rapid adaptation of its strategies.