LayerZero Attributes $290 Million Kelp Exploit to Inadequate Security Setup and North Korean Hackers
LayerZero has attributed the recent $290 million Kelp DAO exploit to a security configuration flaw, specifically a single-verifier setup that the company had previously advised against. The attack, which LayerZero believes with preliminary confidence was carried out by North Korea's Lazarus Group, involved compromising two remote procedure call (RPC) nodes that LayerZero's verifier relied on. These nodes were manipulated to report false transaction data to LayerZero's verifier while maintaining accurate data for other systems. To ensure the attack went undetected, the perpetrators launched a distributed denial-of-service (DDoS) attack on uncompromised external RPC nodes, forcing a failover to the compromised nodes. Once the failover was triggered, the compromised nodes falsely confirmed a cross-chain message, resulting in the release of 116,500 rsETH to the attackers. The attack's success was facilitated by Kelp's use of a 1-of-1 verifier configuration, contrary to LayerZero's recommendations for a multi-verifier setup. LayerZero had emphasized the importance of redundancy and consensus across multiple independent verifiers to prevent such exploits. The company has confirmed that no other applications on the protocol were affected and has since taken steps to prevent similar incidents, including refusing to sign messages for applications with single-verifier configurations. The distinction between a protocol-level bug and a configuration failure is significant, as it suggests that the protocol functioned as intended, and the vulnerability was a result of Kelp's security choices rather than a flaw in LayerZero's code. The Lazarus Group, attributed to the attack, has been linked to another recent exploit, highlighting the group's ability to adapt and target DeFi protocols with varying attack vectors.