LayerZero Attributes $290 Million Kelp Exploit to North Korea's Lazarus, Citing Kelp's Security Setup
LayerZero has attributed the $290 million exploit of Kelp DAO to Kelp's own security configuration, specifically its use of a single-verifier setup despite recommendations for a multi-verifier setup. The attack, which LayerZero believes with preliminary confidence was carried out by North Korea's Lazarus Group and its TraderTraitor subunit, involved the compromise of two remote procedure call (RPC) nodes that LayerZero's verifier relied on. These nodes were manipulated to report fraudulent transactions to LayerZero's verifier while providing accurate data to other systems. To ensure the attack went undetected, the attackers launched a distributed denial-of-service (DDoS) attack on uncompromised external RPC nodes, forcing a failover to the compromised nodes. The DDoS, which occurred between 10:20 a.m. and 11:40 a.m. Pacific Time on Saturday, allowed the attackers to release 116,500 rsETH. The attack's success was facilitated by Kelp's 1-of-1 verifier configuration, which meant LayerZero Labs was the sole entity verifying messages to and from the rsETH bridge. LayerZero had recommended a multi-verifier setup with redundancy, which would have required consensus across several independent verifiers to confirm a message, thereby preventing the attack. The company has confirmed that there was no contagion to any other application on the protocol and that every OFT-standard token and application running multi-verifier setups was unaffected. In response, LayerZero Labs will no longer sign messages for applications running a 1-of-1 configuration, prompting a protocol-wide migration off single-verifier setups. This distinction is significant for how DeFi prices LayerZero risk going forward, as it implies the protocol worked as designed and that Kelp's security choices, rather than LayerZero's code, created the vulnerability. The Lazarus Group has been linked to another recent exploit, the Drift Protocol exploit on April 1, and has drained over $575 million from DeFi in 18 days through two distinct attack vectors.