LayerZero Attributes $290 Million Exploit to Kelp's Setup and North Korea's Lazarus Group

LayerZero has assigned blame for the $290 million Kelp DAO exploit to Kelp's security configuration, stating that the protocol's single-verifier setup, which LayerZero had previously advised against, was the primary cause. The attackers, believed with preliminary confidence to be North Korea's Lazarus Group, infiltrated two remote procedure call (RPC) nodes relied upon by LayerZero's verifier, compromising cross-chain transactions. By swapping the binary software on these nodes with malicious versions, the attackers deceived LayerZero's verifier into confirming a fraudulent transaction while maintaining accurate data for other systems. To ensure the attack went undetected, the attackers launched a distributed denial-of-service attack on uncompromised external RPC nodes, forcing a failover to the compromised nodes. Traffic logs indicate the DDoS occurred between 10:20 a.m. and 11:40 a.m. Pacific Time on Saturday, ultimately resulting in the release of 116,500 rsETH to the attackers. The attack's success can be attributed to Kelp's 1-of-1 verifier configuration, which LayerZero had recommended against in favor of a multi-verifier setup with redundancy. This configuration would have required consensus across multiple independent verifiers to confirm a message, thereby preventing the attack. LayerZero has confirmed that no other applications on the protocol were affected and has since brought its verifier back online, announcing that it will no longer support applications with single-verifier setups. The distinction between a protocol-level bug and a configuration failure is significant, as it implies that the protocol functioned as intended, and Kelp's security choices, rather than LayerZero's code, created the vulnerability. Kelp has yet to publicly address LayerZero's claims or explain its decision to operate a 1-of-1 verifier setup despite explicit warnings. The Lazarus Group, linked to the Drift Protocol exploit on April 1 and now the Kelp exploit on April 18, has drained over $575 million from DeFi in 18 days, demonstrating its ability to adapt its tactics faster than DeFi protocols can fortify their defenses.