LayerZero Attributes $290 Million Kelp DAO Exploit to Inadequate Security Setup and North Korea's Lazarus Group
LayerZero has attributed the recent $290 million Kelp DAO exploit to Kelp's own security configuration, stating that the protocol's single-verifier setup, which they had previously warned against, was the primary factor in the attack's success. The attack, which LayerZero believes with preliminary confidence was carried out by North Korea's Lazarus Group and its TraderTraitor subunit, involved the compromise of two remote procedure call (RPC) nodes used by LayerZero's verifier to confirm cross-chain transactions. These nodes were manipulated to report false data to LayerZero's verifier while continuing to provide accurate information to other systems, effectively hiding the attack from LayerZero's monitoring infrastructure. To ensure the success of the exploit, the attackers also launched a distributed denial-of-service (DDoS) attack on uncompromised external RPC nodes, forcing a failover to the compromised nodes. Once the failover was triggered, the compromised nodes falsely verified a cross-chain message, resulting in the release of 116,500 rsETH to the attackers. The malicious software then self-destructed, erasing any evidence of the attack. LayerZero emphasizes that the attack would not have been possible if Kelp had implemented a multi-verifier setup with redundancy, as recommended. This configuration would have required consensus across several independent verifiers to confirm a message, making it more difficult for attackers to forge a valid message. LayerZero has confirmed that there was no contagion to other applications on the protocol and has since brought its verifier back online, announcing that it will no longer support applications with single-verifier setups. The distinction between a protocol-level bug and a configuration failure is significant, as it implies that the protocol functioned as designed and that Kelp's security choices, rather than LayerZero's code, created the vulnerability. The Lazarus Group has been linked to two major exploits in 18 days, including the Drift Protocol exploit on April 1, draining over $575 million from DeFi through structurally different attack vectors.