LayerZero Attributes $290 Million Exploit to Kelp's Security Setup and North Korea's Lazarus Group
LayerZero has attributed the recent $290 million exploit of Kelp DAO to Kelp's own security configuration, specifically its use of a single-verifier setup despite recommendations for a multi-verifier configuration. The attack, which LayerZero believes with preliminary confidence was carried out by North Korea's Lazarus Group and its TraderTraitor subunit, involved the compromise of two remote procedure call (RPC) nodes used by LayerZero's verifier. These nodes were manipulated to report false data to LayerZero's verifier while continuing to provide accurate data to other systems, thus avoiding detection by LayerZero's monitoring infrastructure. To ensure the attack's success, the perpetrators also launched a distributed denial-of-service (DDoS) attack on uncompromised external RPC nodes, forcing a failover to the compromised nodes. The attack resulted in the release of 116,500 rsETH to the attackers. LayerZero emphasizes that the exploit was only possible due to Kelp's single-verifier setup and notes that it had recommended a multi-verifier configuration with redundancy to prevent such attacks. The company confirms that there has been no contagion to other applications on the protocol and that it will no longer support single-verifier setups. This incident highlights the importance of robust security configurations in preventing exploits and the need for DeFi protocols to continually adapt and harden their defenses against evolving threats.