LayerZero Points to Kelp's Security Setup as Cause of $290 Million Exploit, Links Attack to North Korea's Lazarus Group

LayerZero has attributed the $290 million exploit of Kelp DAO to a security configuration flaw on Kelp's part, stating that the protocol's single-verifier setup, which LayerZero had warned against, was the primary cause of the vulnerability. The attack, which LayerZero believes with preliminary confidence was carried out by North Korea's Lazarus Group, involved the compromise of two remote procedure call (RPC) nodes that LayerZero's verifier relied on for cross-chain transactions. These nodes were manipulated to report false transaction data to LayerZero's verifier while maintaining accurate data for other systems. To ensure the attack went undetected, the attackers also launched a distributed denial-of-service (DDoS) attack on other external RPC nodes, forcing a failover to the compromised nodes. The DDoS, which occurred between 10:20 a.m. and 11:40 a.m. Pacific Time on Saturday, allowed the attackers to release 116,500 rsETH. The attack's success was contingent upon Kelp's use of a 1-of-1 verifier configuration, contrary to LayerZero's recommendations for a multi-verifier setup with redundancy. Such a setup would have required consensus across multiple independent verifiers to confirm a message, thereby preventing the attack. LayerZero has confirmed that there was no contagion to other applications on the protocol and has since brought its verifier back online, announcing that it will no longer support applications with single-verifier configurations. This distinction is crucial for DeFi's risk assessment of LayerZero going forward, as it indicates that the protocol functioned as designed and the exploit was a result of Kelp's security choices rather than a protocol-level bug. The Lazarus Group, linked to both the Kelp and Drift Protocol exploits, has drained over $575 million from DeFi in 18 days, demonstrating its ability to adapt its attack strategies rapidly.