LayerZero Points to Kelp's Security Setup as Cause of $290 Million Exploit, Links Attack to North Korea's Lazarus Group

LayerZero has attributed the $290 million Kelp DAO exploit to Kelp's security configuration, stating that the protocol's single-verifier setup, which LayerZero had warned against, was the root cause of the vulnerability. The attack, which LayerZero believes with preliminary confidence was carried out by North Korea's Lazarus Group and its TraderTraitor subunit, involved the compromise of two remote procedure call (RPC) nodes used by LayerZero's verifier to confirm cross-chain transactions. By replacing the binary software on these nodes with malicious versions, the attackers were able to deceive LayerZero's verifier into believing a fraudulent transaction had occurred, while maintaining accurate data for other systems. To ensure the attack went undetected, the attackers launched a distributed denial-of-service attack on uncompromised external RPC nodes, forcing a failover to the compromised nodes. This allowed the attackers to release 116,500 rsETH, after which the malicious node software self-destructed, erasing binaries and local logs. The success of the attack was facilitated by Kelp's 1-of-1 verifier configuration, which meant that only one entity was verifying messages to and from the rsETH bridge. LayerZero had recommended a multi-verifier setup with redundancy, which would have required consensus across several independent verifiers to confirm a message, thereby preventing the attack. LayerZero has confirmed that there was no contagion to other applications on the protocol and has since brought its verifier back online, announcing that it will no longer sign messages for applications running a 1-of-1 configuration. The distinction between a protocol-level bug and a configuration failure is significant for how DeFi prices LayerZero risk going forward, as it implies that the protocol functioned as designed and that Kelp's security choices, rather than LayerZero's code, created the vulnerability. Kelp has yet to publicly respond to LayerZero's account of the events or explain why it chose to operate a 1-of-1 verifier setup despite explicit recommendations against it. The Lazarus Group has been linked to two major exploits in 18 days, including the Drift Protocol exploit on April 1 and the Kelp exploit on April 18, resulting in the drainage of over $575 million from DeFi through two distinct attack vectors.