LayerZero Points to Kelp's Security Setup as Cause of $290 Million Exploit, Links Attack to North Korea's Lazarus Group
LayerZero has attributed the recent $290 million Kelp DAO exploit to a security configuration issue on Kelp's part, specifically the use of a single-verifier setup that the company had previously advised against. According to LayerZero, the attack, which is preliminarily linked to North Korea's Lazarus Group and its TraderTraitor subunit, exploited a novel vector targeting the infrastructure layer rather than the protocol code itself. The attackers compromised two remote procedure call (RPC) nodes that LayerZero's verifier relied on, swapping their binary software with malicious versions designed to deceive LayerZero's verifier into confirming fraudulent transactions while reporting accurate data to other systems. To ensure the attack remained undetected by LayerZero's monitoring infrastructure, the attackers also launched a distributed denial-of-service (DDoS) attack on uncompromised external RPC nodes, forcing a failover to the compromised nodes. This DDoS attack, which occurred between 10:20 a.m. and 11:40 a.m. Pacific Time on Saturday, allowed the attackers to release 116,500 rsETH. The malicious node software then self-destructed, erasing binaries and local logs. LayerZero emphasizes that the attack's success was contingent upon Kelp's 1-of-1 verifier configuration, which meant LayerZero Labs was the sole entity verifying messages to and from the rsETH bridge. In contrast, a multi-verifier setup with redundancy, as recommended by LayerZero, would have required consensus across several independent verifiers to confirm a message, thereby preventing the attack. LayerZero has confirmed that there was no contagion to other applications on the protocol and that all OFT-standard tokens and applications using multi-verifier setups were unaffected. In response to the incident, LayerZero Labs has brought its verifier back online and will no longer sign messages for applications running a 1-of-1 configuration, effectively necessitating a protocol-wide migration away from single-verifier setups. This distinction is crucial for how DeFi assesses LayerZero risk, as it indicates that the protocol functioned as designed, and the vulnerability was a result of Kelp's security choices rather than a protocol-level bug. Kelp has yet to publicly address LayerZero's claims or explain why it opted for a 1-of-1 verifier setup despite explicit recommendations against it. The Lazarus Group, linked to the recent Drift Protocol exploit on April 1, has now been implicated in the Kelp exploit on April 18, cumulatively draining over $575 million from DeFi in 18 days through two distinct attack vectors, highlighting the group's rapid adaptation of its tactics.