LayerZero Attributes $290 Million Exploit to Kelp's Security Setup and North Korea's Lazarus Group
LayerZero has attributed the $290 million Kelp DAO exploit to Kelp's own security configuration, specifically the use of a single-verifier setup despite recommendations for a multi-verifier configuration. The attack, which LayerZero believes with preliminary confidence was carried out by North Korea's Lazarus Group, involved compromising two remote procedure call (RPC) nodes that LayerZero's verifier relied on for cross-chain transactions. The attackers replaced the binary software on these nodes with malicious versions that reported fraudulent transactions to LayerZero's verifier while providing accurate data to other systems. To ensure the attack went undetected, the attackers also launched a distributed denial-of-service (DDoS) attack on uncompromised external RPC nodes, forcing failover to the compromised nodes. The attack resulted in the release of 116,500 rsETH to the attackers. LayerZero emphasized that the attack was only possible due to Kelp's single-verifier setup and noted that its public integration checklist and direct communications had recommended a multi-verifier setup with redundancy. The company confirmed that there was no contagion to other applications on the protocol and that every OFT-standard token and application running multi-verifier setups was unaffected. In response to the attack, LayerZero Labs will no longer sign messages for applications running a 1-of-1 configuration, effectively requiring a protocol-wide migration to multi-verifier setups. The distinction between a protocol-level bug and a configuration failure is significant for how DeFi prices LayerZero risk. While a protocol-level bug would have implied that every OFT token on every chain was at risk, the fact that the exploit was due to Kelp's security choices and a targeted infrastructure attack suggests that the protocol functioned as designed. Kelp has not publicly responded to LayerZero's account of the exploit or explained why it operated a 1-of-1 verifier setup despite the recommendations against it. The Lazarus Group, which has been linked to the Drift Protocol exploit on April 1, has now drained over $575 million from DeFi in 18 days through two distinct attack vectors, highlighting the group's ability to adapt its playbook faster than DeFi protocols can harden their defenses.