LayerZero Attributes $290 Million Kelp Exploit to North Korea's Lazarus, Citing Kelp's Security Setup

LayerZero has attributed the $290 million exploit of Kelp DAO to a security configuration issue on Kelp's part, stating that the protocol's single-verifier setup, which LayerZero had previously advised against, was the primary factor. The attack, believed to be the work of North Korea's Lazarus Group, involved the compromise of two RPC nodes that LayerZero's verifier relied on for cross-chain transactions. These nodes were manipulated to provide false information to LayerZero's verifier while maintaining accurate data for other systems. To ensure the attack went undetected, the attackers launched a distributed denial-of-service attack on uncompromised external RPC nodes, forcing a failover to the compromised nodes. This resulted in the release of 116,500 rsETH to the attackers. The attack's success was directly tied to Kelp's use of a 1-of-1 verifier configuration, contrary to LayerZero's recommendations for a multi-verifier setup with redundancy. LayerZero has confirmed that no other applications on the protocol were affected and has since gone back online, with plans to require a migration away from single-verifier setups. The distinction between a protocol-level bug and a configuration failure is significant, as it implies the protocol functioned as intended, and the vulnerability was due to Kelp's security choices rather than LayerZero's code. This incident, coupled with the Drift Protocol exploit, highlights the evolving nature of attacks by the Lazarus Group, which has drained over $575 million from DeFi protocols in a short span.