LayerZero Attributes $290 Million Kelp Exploit to Inadequate Security Setup and North Korea's Lazarus Group
LayerZero has stated that the $290 million exploit of Kelp DAO is a direct result of Kelp's security configuration, which involved a single-verifier setup that the company had previously advised against. The attack, attributed to North Korea's Lazarus Group with preliminary confidence, exploited a novel vector targeting the infrastructure layer rather than the protocol code itself. The attackers compromised two remote procedure call (RPC) nodes that LayerZero's verifier relied on, swapping the binary software with malicious versions designed to deceive the verifier about a fraudulent transaction. This was made possible by Kelp's failure to implement a multi-verifier setup with redundancy, as recommended by LayerZero. The attack was further facilitated by a distributed denial-of-service attack on uncompromised external RPC nodes, forcing a failover to the compromised nodes. LayerZero has confirmed that the attack only succeeded due to Kelp's 1-of-1 verifier configuration and has emphasized the importance of a multi-verifier setup for security. The company has also announced that it will no longer sign messages for applications running a 1-of-1 configuration, prompting a protocol-wide migration to more secure setups. This distinction is crucial for how DeFi prices LayerZero risk, as the exploit was a result of Kelp's security choices rather than a protocol-level bug.