LayerZero Attributes $290 Million Kelp Exploit to North Korea's Lazarus, Citing Inadequate Security Setup
LayerZero has pinned the blame for the $290 million Kelp DAO exploit on Kelp's own security configuration, specifically the use of a single-verifier setup that the company had previously advised against. The attack, attributed to North Korea's Lazarus Group, involved compromising two remote procedure call (RPC) nodes that LayerZero's verifier relied on, and then launching a distributed denial-of-service (DDoS) attack on the remaining nodes to force a failover to the compromised ones. This allowed the attackers to trick LayerZero's verifier into releasing 116,500 rsETH. The attack's success is attributed to Kelp's failure to implement a multi-verifier setup with redundancy, which would have required consensus across several independent verifiers to confirm a message. LayerZero had recommended this setup to Kelp, and its absence made the attack possible. The company has confirmed that there was no contagion to other applications on the protocol and has since taken the LayerZero Labs verifier offline, vowing not to sign messages for any application using a single-verifier configuration. This incident highlights the importance of security configurations in DeFi and the need for protocols to harden their defenses against evolving threats.