LayerZero Attributes $290 Million Kelp Exploit to Lazarus Group, Citing Configuration Flaws

LayerZero has attributed the $290 million exploit of Kelp DAO to a security configuration flaw, stating that the protocol's single-verifier setup, which the company had warned against, was the primary cause of the vulnerability. The attack, which LayerZero believes with preliminary confidence was carried out by North Korea's Lazarus Group, involved the compromise of two remote procedure call (RPC) nodes that LayerZero's verifier relied on for cross-chain transactions. The attackers replaced the legitimate software on these nodes with malicious versions, which reported false data to LayerZero's verifier while maintaining accurate data for other systems. To ensure the attack remained undetected, the attackers launched a distributed denial-of-service (DDoS) attack on the uncompromised external RPC nodes, forcing a failover to the compromised nodes. The attack resulted in the release of 116,500 rsETH to the attackers. LayerZero emphasizes that the breach would have been prevented if Kelp had implemented a multi-verifier setup with redundancy, as recommended. The company has confirmed that there was no contagion to other applications on the protocol and has since taken the LayerZero Labs verifier offline, announcing that it will no longer support applications with single-verifier configurations. This incident highlights the importance of robust security configurations in DeFi protocols and the evolving nature of attacks, with Lazarus Group linked to over $575 million in DeFi losses in just 18 days.