LayerZero Attributes $290 Million Exploit to Kelp's Security Setup and North Korea's Lazarus Group

LayerZero has attributed the $290 million Kelp DAO exploit to Kelp's security configuration, stating that the protocol's single-verifier setup, which LayerZero had previously advised against, was the primary factor in the attack. The attackers, believed to be associated with North Korea's Lazarus Group, compromised two remote procedure call (RPC) nodes used by LayerZero's verifier, allowing them to manipulate transaction data. The attack was made possible by Kelp's failure to implement a multi-verifier setup, which would have required consensus across multiple independent verifiers to confirm a message. LayerZero's verifier relied on a combination of internal and external RPC nodes for redundancy, but the attackers were able to swap the binary software on two of the nodes with malicious versions, allowing them to report fraudulent transactions to LayerZero's verifier while maintaining accurate data for other systems. The attackers also launched a distributed denial-of-service (DDoS) attack on the uncompromised external RPC nodes, forcing failover to the compromised nodes. Once the failover was triggered, the compromised nodes informed the verifier that a valid cross-chain message had been received, resulting in the release of 116,500 rsETH to the attackers. LayerZero has confirmed that there was no contagion to other applications on the protocol and has stated that it will no longer sign messages for applications using a single-verifier setup, effectively requiring a protocol-wide migration to multi-verifier configurations. The distinction between a protocol-level bug and a configuration failure is significant, as it implies that the protocol functioned as intended, and the exploit was the result of Kelp's security choices rather than a flaw in LayerZero's code. Lazarus Group has been linked to two major exploits in the past 18 days, including the Drift Protocol exploit on April 1 and the Kelp exploit on April 18, resulting in the theft of over $575 million from DeFi protocols.