LayerZero Attributes $290 Million Kelp Exploit to Inadequate Security Setup and North Korea's Lazarus Group
LayerZero has assigned blame for the $290 million Kelp DAO breach to Kelp's own security setup, citing the protocol's use of a single verifier despite previous warnings against this practice. According to LayerZero, the attackers, believed with preliminary confidence to be North Korea's Lazarus Group, infiltrated two RPC nodes that LayerZero's verifier relied on, manipulating them to validate a fraudulent transaction while keeping the attack hidden from LayerZero's monitoring systems. The attackers also launched a DDoS attack on uncompromised external RPC nodes to force failover to the compromised ones, resulting in the release of 116,500 rsETH to the attackers. LayerZero emphasizes that the attack's success was contingent upon Kelp's single-verifier configuration, which disregarded recommendations for a multi-verifier setup that would have required consensus across several independent verifiers to confirm a message. This configuration failure, combined with the targeted infrastructure attack, indicates that the protocol functioned as designed, and the vulnerability was created by Kelp's security choices rather than any flaw in LayerZero's code. LayerZero has confirmed that there was no contagion to other applications on the protocol and has since taken the verifier offline, announcing that it will no longer support applications with single-verifier setups. The distinction between a protocol-level bug and a configuration failure is significant for how DeFi assesses LayerZero risk. Meanwhile, Lazarus Group has been linked to over $575 million in DeFi losses in just 18 days, adapting its tactics faster than DeFi protocols can strengthen their defenses.