LayerZero Attributes $290 Million Kelp DAO Exploit to North Korea's Lazarus Group, Citing Kelp's Security Setup

LayerZero has attributed the $290 million Kelp DAO exploit to Kelp's own security configuration, stating that the protocol's single-verifier setup, which LayerZero had warned against, was the root cause of the vulnerability. The attack, which LayerZero believes with preliminary confidence was carried out by North Korea's Lazarus Group and its TraderTraitor subunit, involved the compromise of two remote procedure call (RPC) nodes that LayerZero's verifier relied on to validate cross-chain transactions. By swapping the binary software on these nodes with malicious versions, the attackers were able to deceive LayerZero's verifier into confirming a fraudulent transaction while maintaining accurate data for other systems. The attackers also launched a distributed denial-of-service (DDoS) attack on uncompromised external RPC nodes to force failover to the compromised nodes. The DDoS attack, which occurred between 10:20 a.m. and 11:40 a.m. Pacific Time on Saturday, triggered the release of 116,500 rsETH to the attackers. The malicious node software then self-destructed, erasing binaries and local logs. LayerZero emphasized that the attack was only successful because Kelp used a 1-of-1 verifier configuration, contrary to LayerZero's recommendations for a multi-verifier setup with redundancy. The company has confirmed that there was no contagion to other applications on the protocol and has announced that it will no longer sign messages for applications with single-verifier configurations, effectively requiring a protocol-wide migration to multi-verifier setups. This distinction is significant for how DeFi prices LayerZero risk, as a protocol-level bug would have implied a broader risk, whereas the configuration failure and targeted infrastructure attack suggest that the protocol functioned as designed. Kelp has not publicly responded to LayerZero's account of the incident or explained why it operated a 1-of-1 verifier setup despite explicit recommendations against it. The Lazarus Group has been linked to two major exploits in 18 days, including the Drift Protocol exploit on April 1 and the Kelp exploit on April 18, resulting in the loss of over $575 million from DeFi protocols through distinct attack vectors.