LayerZero Attributes $290 Million Kelp Exploit to Inadequate Security Setup and North Korea's Lazarus Group
LayerZero has attributed the $290 million exploit of Kelp DAO to the protocol's single-verifier setup, a configuration that the company had previously advised against. The attack, which LayerZero believes with preliminary confidence was carried out by North Korea's Lazarus Group, involved the compromise of two remote procedure call (RPC) nodes used by LayerZero's verifier for cross-chain transactions. These nodes were manipulated to report false transaction data to LayerZero's verifier while maintaining accurate data for other systems, effectively hiding the attack from LayerZero's monitoring. To ensure the success of the exploit, the attackers also launched a distributed denial-of-service (DDoS) attack on uncompromised external RPC nodes, forcing a failover to the compromised nodes. This led to the release of 116,500 rsETH to the attackers. LayerZero emphasizes that the attack's success was contingent upon Kelp's use of a 1-of-1 verifier configuration, contrary to recommendations for a multi-verifier setup that would have required consensus across several verifiers to confirm a message, thereby preventing the exploit. The company has confirmed no contagion to other applications on the protocol and has resumed operations, stating it will no longer support applications with single-verifier setups. This distinction is crucial as it implies the exploit was a result of Kelp's security choices rather than a flaw in LayerZero's protocol. The Lazarus Group, attributed to this exploit, has been linked to over $575 million in DeFi losses in just 18 days, highlighting the group's rapid adaptation of attack strategies.