LayerZero Attributes $290 Million Kelp Exploit to Inadequate Security Setup and North Korea's Lazarus Group

LayerZero has attributed the $290 million exploit of Kelp DAO to the protocol's allegedly inadequate security configuration, specifically its use of a single-verifier setup despite previous warnings against such a configuration. The attack, which LayerZero believes with preliminary confidence to be the work of North Korea's Lazarus Group and its TraderTraitor subunit, exploited a novel vector targeting the infrastructure layer. The attackers compromised two remote procedure call (RPC) nodes that LayerZero's verifier relied on, swapping their software with malicious versions designed to deceive LayerZero's verifier about a fraudulent transaction while reporting accurate data to other systems. To ensure the attack went undetected by LayerZero's monitoring, which uses different IP addresses to query the same RPCs, the attackers launched a distributed denial-of-service (DDoS) attack on uncompromised external RPC nodes. This forced a failover to the compromised nodes, resulting in the release of 116,500 rsETH to the attackers. The malicious software then self-destructed, erasing binaries and local logs. LayerZero emphasizes that the attack's success was due to Kelp's 1-of-1 verifier configuration, contrary to recommendations for a multi-verifier setup with redundancy. Such a setup would have required consensus across multiple independent verifiers to confirm a message, thereby preventing the forging of a valid message through the poisoning of a single verifier's data feed. LayerZero has confirmed that there was no contagion to other applications on the protocol and that every OFT-standard token and application using multi-verifier setups was unaffected. In response, LayerZero Labs will no longer sign messages for applications running 1-of-1 configurations, prompting a protocol-wide migration away from single-verifier setups. This architectural distinction is significant for how DeFi assesses LayerZero risk, as it indicates the protocol functioned as designed, and the vulnerability was a result of Kelp's security choices rather than a protocol-level bug. The exploit is the second major attack attributed to the Lazarus Group in 18 days, following the Drift Protocol exploit, together totaling over $575 million drained from DeFi through different attack vectors.