LayerZero Attributes $290 Million Exploit to Kelp's Security Setup and North Korea's Lazarus Group
LayerZero has attributed the $290 million Kelp DAO exploit to Kelp's own security configuration, stating that the liquid restaking protocol's single-verifier setup, which LayerZero had previously advised against, was the primary factor in the attack. The exploit utilized a novel approach targeting the infrastructure layer rather than the protocol code itself. According to LayerZero, the attackers, who are believed with preliminary confidence to be associated with North Korea's Lazarus Group and its TraderTraitor subunit, compromised two of the RPC nodes that LayerZero's verifier relied on for cross-chain transaction verification. These RPC nodes, which are servers that allow software to read and write data on a blockchain, were a mix of internal and external nodes used by LayerZero's verifier for redundancy. The attackers replaced the legitimate binary software on the compromised nodes with malicious versions designed to deceive LayerZero's verifier into confirming a fraudulent transaction, while still providing accurate data to other systems querying those nodes. This selective deception was engineered to remain undetected by LayerZero's monitoring infrastructure, which queries the same RPCs from different IP addresses. Compromising two nodes was insufficient, as LayerZero's verifier also queried uncompromised external RPC nodes. Therefore, the attackers launched a distributed denial-of-service attack on those nodes to force a failover to the compromised ones. Traffic logs provided by LayerZero indicate that the DDoS occurred between 10:20 a.m. and 11:40 a.m. Pacific Time on Saturday. Once the failover was triggered, the compromised nodes informed the verifier that a valid cross-chain message had arrived, resulting in Kelp's bridge releasing 116,500 rsETH to the attackers. The malicious node software then self-destructed, erasing binaries and local logs. The attack's success can be attributed to Kelp's 1-of-1 verifier configuration, where LayerZero Labs was the sole entity verifying messages to and from the rsETH bridge. LayerZero's public integration checklist and direct communications to Kelp had recommended a multi-verifier setup with redundancy, which would have required consensus across several independent verifiers to confirm a message. Under such a configuration, compromising one verifier's data feed would not have been sufficient to forge a valid message. LayerZero has confirmed that there was no contagion to any other application on the protocol, with all OFT-standard tokens and applications running multi-verifier setups remaining unaffected. The LayerZero Labs verifier is now back online, and the company has announced that it will no longer sign messages for any application using a 1-of-1 configuration, effectively mandating a protocol-wide migration away from single-verifier setups. This distinction is significant for how DeFi prices LayerZero risk going forward. A protocol-level bug would have implied that every OFT token on every chain was potentially at risk. However, a configuration failure by a single integrator combined with a targeted infrastructure attack suggests that the protocol functioned as designed and that Kelp's security choices, rather than LayerZero's code, created the vulnerability. Kelp has yet to publicly respond to LayerZero's account of events or address why it operated a 1-of-1 verifier setup despite explicit recommendations against it. The Lazarus Group has been linked to both the Drift Protocol exploit on April 1 and the Kelp exploit on April 18, resulting in the drainage of over $575 million from DeFi in 18 days through two distinct attack vectors: social engineering governance signers at Drift and poisoning infrastructure RPCs at Kelp. This indicates that the group is adapting its tactics faster than DeFi protocols are strengthening their defenses.