LayerZero Points to Kelp's Security Setup as Cause of $290 Million Exploit, Links Attack to North Korea's Lazarus Group

LayerZero has attributed the $290 million exploit of Kelp DAO to a security configuration issue on Kelp's part, specifically the use of a single-verifier setup despite recommendations for a multi-verifier configuration. The attack, which LayerZero believes with initial confidence was conducted by North Korea's Lazarus Group and its TraderTraitor subunit, exploited the infrastructure layer by compromising two remote procedure call (RPC) nodes that LayerZero's verifier relied on. These nodes were tricked into validating a fraudulent transaction while maintaining accurate data for other systems, thus evading detection by LayerZero's monitoring. To ensure the attack's success, the perpetrators also launched a distributed denial-of-service (DDoS) attack on uncompromised external RPC nodes, forcing a failover to the compromised nodes. Logs show the DDoS occurred between 10:20 a.m. and 11:40 a.m. Pacific Time on Saturday, resulting in the release of 116,500 rsETH to the attackers. The malicious software then self-destructed, erasing binaries and local logs. LayerZero emphasizes that the attack was only possible due to Kelp's 1-of-1 verifier configuration, contrary to LayerZero's public integration checklist and direct communications recommending a multi-verifier setup for enhanced security. Under a multi-verifier configuration, where consensus across several independent verifiers is required, the attack would not have been successful. LayerZero has confirmed that there was no contagion to other applications on the protocol, with all OFT-standard tokens and applications using multi-verifier setups remaining unaffected. The LayerZero Labs verifier is now back online, and the company has announced it will no longer support applications with single-verifier configurations, prompting a protocol-wide migration to more secure setups. This distinction is crucial for how DeFi assesses LayerZero risk, as a protocol-level bug would have implied a broader risk, whereas a configuration failure combined with a targeted infrastructure attack suggests the protocol functioned as designed, with Kelp's security choices creating the vulnerability. Kelp has not publicly responded to LayerZero's assessment or explained its decision to use a 1-of-1 verifier setup despite the recommendations against it. The Lazarus Group, linked to the Drift Protocol exploit on April 1 and now the Kelp exploit on April 18, has drained over $575 million from DeFi in 18 days through two distinct attack vectors, indicating the group's rapid adaptation of its strategies.