LayerZero Attributes $290 Million Kelp DAO Exploit to Inadequate Security Setup and North Korea's Lazarus Group
LayerZero has attributed the recent $290 million Kelp DAO exploit to Kelp's allegedly inadequate security configuration, specifically the use of a single-verifier setup despite prior warnings. The exploit, which LayerZero believes with preliminary confidence was orchestrated by North Korea's Lazarus Group, involved the compromise of two remote procedure call (RPC) nodes used by LayerZero's verifier for cross-chain transactions. These nodes were manipulated to report fraudulent transactions to LayerZero's verifier while providing accurate data to other querying systems, thereby evading detection by LayerZero's monitoring infrastructure. To ensure the success of the attack, the perpetrators also executed a distributed denial-of-service (DDoS) attack on uncompromised external RPC nodes, forcing a failover to the compromised nodes. This DDoS attack occurred between 10:20 a.m. and 11:40 a.m. Pacific Time on Saturday, as evidenced by traffic logs shared by LayerZero. The attack's success was contingent upon Kelp's 1-of-1 verifier configuration, which meant that LayerZero Labs was the sole entity verifying messages to and from the rsETH bridge. LayerZero had previously recommended a multi-verifier setup with redundancy to Kelp, emphasizing the importance of consensus across several independent verifiers for confirming messages. Such a configuration would have prevented the attack, as poisoning one verifier's data feed would not have been sufficient to forge a valid message. LayerZero has confirmed that there was no contagion to any other application on the protocol, with all OFT-standard tokens and applications running multi-verifier setups remaining unaffected. In response to the incident, LayerZero Labs has reinstated its verifier and announced that it will no longer sign messages for applications with 1-of-1 configurations, effectively mandating a protocol-wide migration to multi-verifier setups. This distinction is crucial for DeFi's risk assessment of LayerZero going forward, as it differentiates between a protocol-level bug, which would imply a broader risk, and a configuration failure by a single integrator combined with a targeted infrastructure attack. The latter suggests that the protocol functioned as designed, and it was Kelp's security choices, rather than LayerZero's code, that created the vulnerability. Kelp has yet to publicly address LayerZero's account of the events or explain its decision to operate a 1-of-1 verifier setup despite explicit recommendations against it. The Lazarus Group, linked to the Drift Protocol exploit on April 1 and now the Kelp exploit on April 18, has drained over $575 million from DeFi within 18 days through two distinct attack vectors, highlighting the group's rapid adaptation of its tactics and the ongoing challenge for DeFi protocols to enhance their defenses.