LayerZero Attributes $290 Million Kelp Exploit to Inadequate Security Setup and North Korea's Lazarus Group
LayerZero has attributed the $290 million exploit of Kelp DAO to a security configuration issue, stating that Kelp's use of a single-verifier setup made it vulnerable to the attack. The attack, which LayerZero believes with preliminary confidence was carried out by North Korea's Lazarus Group and its TraderTraitor subunit, involved the compromise of two remote procedure call (RPC) nodes that LayerZero's verifier relied on. These nodes were tricked into reporting false transaction data, while continuing to provide accurate data to other systems. To ensure the attack went undetected, the attackers launched a distributed denial-of-service (DDoS) attack on uncompromised external RPC nodes, forcing a failover to the compromised nodes. LayerZero emphasizes that the attack was only successful because Kelp ignored recommendations for a multi-verifier setup, which would have required consensus across several independent verifiers to confirm a message. The company has confirmed that there was no contagion to other applications on the protocol and has announced that it will no longer support single-verifier configurations, pushing for a protocol-wide migration to more secure setups. This incident highlights the importance of robust security configurations in DeFi and the evolving threats posed by groups like Lazarus, which have been linked to over $575 million in DeFi exploits in just 18 days.