LayerZero Pins $290 Million Exploit on Kelp's Security Setup, Points to North Korea's Lazarus Group

LayerZero has attributed the $290 million Kelp DAO exploit to Kelp's own security configuration, specifically the use of a single-verifier setup despite recommendations for a multi-verifier configuration. The attack, which LayerZero believes with preliminary confidence was carried out by North Korea's Lazarus Group and its TraderTraitor subunit, involved the compromise of two remote procedure call (RPC) nodes that LayerZero's verifier relied on for cross-chain transactions. These nodes were swapped with malicious versions that reported fraudulent transactions to LayerZero's verifier while providing accurate data to other systems. To ensure the attack remained undetected by LayerZero's monitoring infrastructure, the attackers launched a distributed denial-of-service (DDoS) attack on uncompromised external RPC nodes, forcing a failover to the compromised nodes. Traffic logs indicate the DDoS occurred between 10:20 a.m. and 11:40 a.m. Pacific Time on Saturday, resulting in Kelp's bridge releasing 116,500 rsETH to the attackers. The attack's success was contingent upon Kelp's 1-of-1 verifier configuration, which LayerZero had advised against in favor of a multi-verifier setup with redundancy. Such a configuration would have required consensus across several independent verifiers to confirm a message, thereby preventing the attack. LayerZero has confirmed that there was no contagion to other applications on the protocol and has since brought its verifier back online, announcing it will no longer support applications with single-verifier setups. This incident highlights the distinction between protocol-level bugs and configuration failures, with the latter implying that the protocol functioned as designed but was vulnerable due to the integrator's security choices. The Lazarus Group, linked to both the Drift Protocol exploit on April 1 and the Kelp exploit on April 18, has drained over $575 million from DeFi in 18 days using different attack vectors, underscoring the need for DeFi protocols to enhance their defenses.