LayerZero Attributes $290 Million Kelp Exploit to Inadequate Security Setup and North Korean Hackers
LayerZero has attributed the $290 million exploit of Kelp DAO to a security configuration flaw, stating that the protocol's single-verifier setup, which the company had previously warned against, was the primary cause. The attack, which LayerZero believes with preliminary confidence was carried out by North Korea's Lazarus Group and its TraderTraitor subunit, involved the compromise of two remote procedure call (RPC) nodes that LayerZero's verifier relied on for cross-chain transactions. By swapping the binary software on these nodes with malicious versions, the attackers were able to deceive LayerZero's verifier into confirming a fraudulent transaction while maintaining accurate data for other systems. To ensure the attack went undetected, the attackers launched a distributed denial-of-service attack on uncompromised external RPC nodes, forcing a failover to the compromised nodes. Once the failover was triggered, the compromised nodes confirmed a valid cross-chain message, resulting in the release of 116,500 rsETH to the attackers. The attack was only successful due to Kelp's 1-of-1 verifier configuration, which meant that LayerZero Labs was the sole entity verifying messages to and from the rsETH bridge. LayerZero had recommended a multi-verifier setup with redundancy, which would have required consensus across several independent verifiers to confirm a message, thereby preventing the attack. Following the incident, LayerZero has confirmed that there was no contagion to other applications on the protocol and has announced that it will no longer sign messages for applications running a 1-of-1 configuration, effectively forcing a protocol-wide migration to multi-verifier setups. The distinction between a protocol-level bug and a configuration failure is significant, as it implies that the protocol functioned as designed, and the vulnerability was created by Kelp's security choices rather than a flaw in LayerZero's code. The Lazarus Group, which has been linked to the Drift Protocol exploit on April 1, has now drained over $575 million from DeFi in 18 days through two distinct attack vectors, highlighting the group's ability to adapt its tactics faster than DeFi protocols can strengthen their defenses.