LayerZero Attributes $290 Million Kelp Exploit to North Korea's Lazarus, Citing Kelp's Security Setup

LayerZero has attributed the $290 million Kelp DAO exploit to Kelp's own security configuration, stating that the protocol's single-verifier setup, which LayerZero had warned against, was the primary cause of the vulnerability. The attack, believed to be carried out by North Korea's Lazarus Group, involved the compromise of two remote procedure call (RPC) nodes that LayerZero's verifier relied on, allowing the attackers to manipulate the system into releasing 116,500 rsETH. The attack's success was facilitated by Kelp's failure to implement a multi-verifier setup with redundancy, as recommended by LayerZero. This configuration would have required consensus across multiple independent verifiers to confirm a message, thereby preventing the poisoning of a single verifier's data feed from being enough to forge a valid message. LayerZero has confirmed that there was no contagion to other applications on the protocol and has since brought its verifier back online, announcing that it will no longer sign messages for applications running single-verifier configurations. The distinction between a protocol-level bug and a configuration failure is significant, as it implies that the protocol functioned as designed, and the vulnerability was a result of Kelp's security choices rather than LayerZero's code. The Lazarus Group, linked to the recent Drift Protocol exploit, has now drained over $575 million from DeFi in 18 days through two distinct attack vectors, highlighting the group's ability to adapt its tactics faster than DeFi protocols can strengthen their defenses.