LayerZero Attributes $290 Million Kelp Exploit to North Korea's Lazarus Group, Citing Security Setup
LayerZero has attributed the $290 million exploit of Kelp DAO to the protocol's security configuration, stating that Kelp's use of a single-verifier setup made it vulnerable to attack. The exploit, which LayerZero believes with preliminary confidence was carried out by North Korea's Lazarus Group, involved the compromise of two remote procedure call (RPC) nodes that LayerZero's verifier relied on. These nodes were tricked into confirming a fraudulent transaction, while continuing to provide accurate data to other systems. To ensure the attack remained undetected, the perpetrators launched a distributed denial-of-service attack on uncompromised external RPC nodes, forcing LayerZero's verifier to rely on the compromised nodes. Once the verifier confirmed the fraudulent transaction, Kelp's bridge released 116,500 rsETH to the attackers. The attack was only successful because Kelp had ignored LayerZero's recommendations to implement a multi-verifier setup, which would have required consensus across several independent verifiers to confirm a message. LayerZero has confirmed that there was no contagion to other applications on the protocol and has since taken the verifier offline, stating that it will no longer support applications with single-verifier configurations. The exploit highlights the importance of robust security measures in DeFi protocols and the need for protocols to adapt quickly to emerging threats.