LayerZero Points to Kelp's Security Setup as Cause of $290 Million Exploit, Links Attack to North Korea's Lazarus Group

LayerZero has attributed the $290 million exploit of Kelp DAO to Kelp's own security configuration, stating that the protocol's single-verifier setup, which LayerZero had previously advised against, was the root cause of the vulnerability. The attack, which LayerZero believes with preliminary confidence was carried out by North Korea's Lazarus Group and its TraderTraitor subunit, involved the compromise of two remote procedure call (RPC) nodes that LayerZero's verifier relied on for cross-chain transaction validation. By swapping the binary software on these nodes with malicious versions, the attackers were able to deceive LayerZero's verifier into confirming a fraudulent transaction while maintaining accurate data for other systems. This selective deception allowed the attack to remain undetected by LayerZero's monitoring infrastructure. To ensure the compromised nodes were used, the attackers launched a distributed denial-of-service (DDoS) attack on the uncompromised external RPC nodes, forcing a failover to the poisoned ones. Logs show the DDoS occurred between 10:20 a.m. and 11:40 a.m. Pacific Time on Saturday, resulting in the release of 116,500 rsETH to the attackers. The attack's success was contingent upon Kelp's 1-of-1 verifier configuration, which meant LayerZero Labs was the sole entity verifying messages to and from the rsETH bridge. LayerZero had recommended a multi-verifier setup with redundancy, which would have required consensus across several independent verifiers to confirm a message, thereby preventing the attack. The company has confirmed that there was no contagion to any other application on the protocol, with all OFT-standard tokens and applications running multi-verifier setups remaining unaffected. In response, LayerZero Labs has stated it will no longer sign messages for applications running a 1-of-1 configuration, prompting a protocol-wide migration away from single-verifier setups. This distinction is significant for DeFi's assessment of LayerZero risk, as it indicates the protocol functioned as designed, and the exploit was a result of Kelp's security choices rather than a flaw in LayerZero's code. Kelp has yet to publicly address LayerZero's account of the exploit or explain why it operated a 1-of-1 verifier setup despite explicit recommendations against it. The Lazarus Group, linked to both the Kelp and Drift Protocol exploits, has drained over $575 million from DeFi in 18 days, demonstrating its ability to adapt its tactics faster than DeFi protocols can strengthen their defenses.