LayerZero Attributes $290 Million Kelp Exploit to Inadequate Security Setup, Points to North Korea's Lazarus Group
LayerZero has attributed the $290 million exploit of Kelp DAO to the protocol's own security configuration, stating that Kelp's use of a single-verifier setup, despite recommendations for a multi-verifier configuration, was the primary cause of the vulnerability. The attack, which LayerZero believes with preliminary confidence was carried out by North Korea's Lazarus Group and its TraderTraitor subunit, involved the compromise of two remote procedure call (RPC) nodes that LayerZero's verifier relied on for cross-chain transaction validation. By swapping the binary software on these nodes with malicious versions, the attackers were able to deceive LayerZero's verifier into confirming a fraudulent transaction while maintaining the illusion of normal operation for other systems. To ensure the attack's success, the perpetrators also launched a distributed denial-of-service (DDoS) attack on uncompromised external RPC nodes, forcing a failover to the compromised nodes. This sophisticated attack was only possible due to Kelp's 1-of-1 verifier setup, which LayerZero had explicitly warned against in favor of a multi-verifier configuration that would require consensus across several independent verifiers to confirm a message. The company has confirmed that there was no contagion to other applications on the protocol and has since brought its verifier back online, announcing that it will no longer support applications with single-verifier setups. This incident highlights the importance of robust security configurations in DeFi protocols and the evolving nature of threats from groups like Lazarus, which has been linked to over $575 million in DeFi losses in just 18 days through diverse attack vectors.