LayerZero Attributes $290 Million Exploit to Kelp's Security Setup and North Korea's Lazarus Group

LayerZero has assigned blame for the $290 million Kelp DAO exploit to Kelp's security configuration, stating that the protocol's single-verifier setup, which was previously warned against, made it vulnerable to attack. The novel attack vector targeted the infrastructure layer, rather than the protocol code itself. Preliminary findings suggest that the attackers, believed to be North Korea's Lazarus Group and its TraderTraitor subunit, compromised two RPC nodes used by LayerZero's verifier to confirm cross-chain transactions. By swapping the binary software on these nodes with malicious versions, the attackers deceived LayerZero's verifier into confirming a fraudulent transaction while providing accurate data to other systems. To prevent detection, the attackers launched a distributed denial-of-service attack on uncompromised external RPC nodes, forcing failover to the compromised nodes. Traffic logs show the DDoS occurred between 10:20 a.m. and 11:40 a.m. Pacific Time on Saturday, resulting in the release of 116,500 rsETH to the attackers. The attack was only successful due to Kelp's 1-of-1 verifier configuration, which allowed the compromised nodes to forge a valid message. LayerZero had previously recommended a multi-verifier setup with redundancy, which would have prevented the attack. The company has confirmed that there was no contagion to other applications on the protocol and has since taken the LayerZero Labs verifier offline, refusing to sign messages for applications with single-verifier setups. This distinction is crucial for how DeFi prices LayerZero risk going forward, as a protocol-level bug would have implied a much broader risk. Instead, the attack highlights the importance of proper security configurations and the need for DeFi protocols to harden their defenses against evolving threats.