LayerZero Attributes $290 Million Kelp DAO Exploit to North Korea's Lazarus Group, Citing Kelp's Security Setup
LayerZero has attributed the responsibility for the $290 million Kelp DAO exploit to Kelp's security configuration, stating that the protocol's single-verifier setup, which LayerZero had warned against, was the primary cause of the breach. The attackers, who LayerZero believes with preliminary confidence to be North Korea's Lazarus Group and its TraderTraitor subunit, targeted the infrastructure layer by compromising two remote procedure call (RPC) nodes that LayerZero's verifier relied on for cross-chain transactions. By swapping the binary software on these nodes with malicious versions, the attackers were able to deceive LayerZero's verifier into confirming a fraudulent transaction while maintaining accurate data for other systems. The attackers then launched a distributed denial-of-service (DDoS) attack on the uncompromised external RPC nodes, forcing a failover to the compromised nodes. This selective deception allowed the attackers to remain undetected by LayerZero's monitoring infrastructure. The DDoS attack, which occurred between 10:20 a.m. and 11:40 a.m. Pacific Time on Saturday, triggered a failover, resulting in Kelp's bridge releasing 116,500 rsETH to the attackers. The malicious node software then self-destructed, wiping binaries and local logs. The attack's success can be attributed to Kelp's 1-of-1 verifier configuration, which meant that LayerZero Labs was the sole entity verifying messages to and from the rsETH bridge. LayerZero's public integration checklist and direct communications to Kelp had recommended a multi-verifier setup with redundancy, which would have required consensus across several independent verifiers to confirm a message, thereby preventing the attack. LayerZero has confirmed that there was no contagion to any other application on the protocol, and every OFT-standard token and application running multi-verifier setups was unaffected. The LayerZero Labs verifier is now back online, and the company will no longer sign messages for applications running 1-of-1 configurations, effectively forcing a protocol-wide migration to multi-verifier setups. This distinction is crucial for how DeFi prices LayerZero risk going forward, as a protocol-level bug would have implied that every OFT token on every chain was potentially at risk. However, the fact that the attack was the result of a configuration failure by a single integrator, combined with a targeted infrastructure attack, suggests that the protocol functioned as designed and that Kelp's security choices, rather than LayerZero's code, created the vulnerability. Kelp has yet to publicly respond to LayerZero's claims or address why it operated a 1-of-1 verifier setup despite the explicit recommendations against it. The Lazarus Group has been linked to the Drift Protocol exploit on April 1 and the Kelp exploit on April 18, resulting in the group draining over $575 million from DeFi in 18 days through two structurally different attack vectors: social engineering governance signers at Drift and poisoning infrastructure RPCs at Kelp. This demonstrates the group's ability to adapt its playbook faster than DeFi protocols can harden their defenses.