LayerZero Attributes $290 Million Exploit to Kelp's Security Setup and North Korea's Lazarus Group
LayerZero has attributed the $290 million Kelp DAO exploit to Kelp's own security configuration, specifically their use of a single-verifier setup despite recommendations for a multi-verifier setup. The attack, which LayerZero believes with preliminary confidence was carried out by North Korea's Lazarus Group and its TraderTraitor subunit, involved the compromise of two remote procedure call (RPC) nodes that LayerZero's verifier relied on. These nodes were manipulated to provide false information to LayerZero's verifier while continuing to provide accurate data to other systems. To ensure the attack went undetected, the attackers also launched a distributed denial-of-service (DDoS) attack on uncompromised external RPC nodes, forcing a failover to the compromised nodes. This allowed the attackers to release 116,500 rsETH. LayerZero emphasizes that the attack was only successful because Kelp used a 1-of-1 verifier configuration and had ignored recommendations for a multi-verifier setup, which would have required consensus across several independent verifiers to confirm a message. The company has confirmed that there was no contagion to other applications on the protocol and that every OFT-standard token and application using multi-verifier setups was unaffected. Following the incident, LayerZero Labs will no longer sign messages for applications running a 1-of-1 configuration, prompting a protocol-wide migration off single-verifier setups. This distinction is significant for how DeFi prices LayerZero risk, as it indicates the protocol functioned as designed, and the vulnerability was due to Kelp's security choices rather than a flaw in LayerZero's code. The Lazarus Group has been linked to another recent exploit, highlighting the group's ability to adapt its tactics and the need for DeFi protocols to enhance their defenses.