LayerZero Attributes $290 Million Kelp DAO Exploit to Inadequate Security Configuration and North Korea's Lazarus Group

LayerZero has attributed the $290 million Kelp DAO exploit to Kelp's own security setup, stating that the protocol's use of a single verifier, despite recommendations for a multi-verifier configuration, made it vulnerable to the attack. The attackers, believed to be from North Korea's Lazarus Group, compromised two RPC nodes used by LayerZero's verifier, which then reported fraudulent transactions while maintaining accurate data for other systems. This selective manipulation allowed the attack to remain undetected by LayerZero's monitoring infrastructure. To ensure the attack's success, the perpetrators also launched a distributed denial-of-service attack on uncompromised external RPC nodes, forcing a failover to the compromised nodes. Once the failover was triggered, the compromised nodes confirmed a valid cross-chain message, resulting in the release of 116,500 rsETH to the attackers. The attack's success was contingent upon Kelp's use of a 1-of-1 verifier configuration, which LayerZero had explicitly advised against in favor of a multi-verifier setup with redundancy. LayerZero has confirmed that no other applications on the protocol were affected and has since taken steps to prevent similar attacks in the future, including refusing to sign messages for applications with single-verifier configurations. The incident highlights the importance of robust security configurations and the evolving nature of threats in the DeFi space, with Lazarus Group having been linked to over $575 million in exploits in just 18 days.