LayerZero Attributes $290 Million Exploit to Kelp's Security Setup, Links Attack to North Korea's Lazarus Group

LayerZero has attributed the $290 million Kelp DAO exploit to Kelp's own security configuration, stating that the liquid restaking protocol's single-verifier setup, despite warnings against it, enabled the attack. The perpetrators, believed with preliminary confidence to be North Korea's Lazarus Group and its TraderTraitor subunit, compromised two RPC nodes used by LayerZero's verifier for cross-chain transactions. These nodes were manipulated to report false data to LayerZero's verifier while providing accurate information to other systems, thus evading detection. To ensure the attack's success, the attackers also conducted a distributed denial-of-service attack on uncompromised external RPC nodes, forcing a failover to the compromised ones. This resulted in the release of 116,500 rsETH to the attackers. LayerZero emphasizes that the attack was only possible due to Kelp's 1-of-1 verifier configuration and notes that its public integration checklist and direct communications had recommended a multi-verifier setup for added security. The company has confirmed no contagion to other applications on the protocol and has resumed operations with the LayerZero Labs verifier, announcing it will no longer support applications with single-verifier setups. This distinction is crucial for assessing LayerZero risk, as the exploit was a result of Kelp's security choices and targeted infrastructure attack rather than a protocol-level bug. Kelp has yet to publicly address LayerZero's claims or explain its decision to operate a 1-of-1 verifier setup despite recommendations against it. The Lazarus Group, linked to the recent Drift Protocol exploit, has now drained over $575 million from DeFi in 18 days through two distinct attack vectors, highlighting the group's rapid adaptation of its tactics.