LayerZero Attributes $290 Million Kelp DAO Exploit to Inadequate Security Setup and North Korea's Lazarus Group

LayerZero has attributed the $290 million exploit of Kelp DAO to Kelp's own security configuration, stating that the protocol's single-verifier setup, which LayerZero had warned against, was the primary factor. The attack, which LayerZero believes with preliminary confidence was carried out by North Korea's Lazarus Group and its TraderTraitor subunit, involved the compromise of two remote procedure call (RPC) nodes used by LayerZero's verifier for cross-chain transactions. These nodes were manipulated to provide false information to LayerZero's verifier while maintaining accurate data for other systems. To ensure the attack remained undetected, the perpetrators also launched a distributed denial-of-service (DDoS) attack on uncompromised external RPC nodes, forcing a failover to the compromised nodes. The attack resulted in the release of 116,500 rsETH to the attackers. LayerZero emphasizes that the exploit was only successful due to Kelp's 1-of-1 verifier configuration and notes that its public integration checklist and direct communications had recommended a multi-verifier setup for added security. The company has confirmed that there was no contagion to other applications on the protocol and has since taken the LayerZero Labs verifier offline, announcing that it will no longer support applications with single-verifier configurations. This incident highlights the importance of security configurations in DeFi protocols and the evolving tactics of groups like the Lazarus Group, which has been linked to over $575 million in DeFi exploits within an 18-day period.