LayerZero Attributes $290 Million Kelp Exploit to Inadequate Security Setup and North Korea's Lazarus Group

LayerZero has shifted the blame for the $290 million Kelp DAO exploit to Kelp's own security configuration, stating that the protocol's single-verifier setup, which LayerZero had previously advised against, was the primary cause of the vulnerability. The attack, attributed with preliminary confidence to North Korea's Lazarus Group and its TraderTraitor subunit, exploited a novel vector targeting the infrastructure layer. The attackers compromised two remote procedure call (RPC) nodes that LayerZero's verifier relied on, swapping the binary software with malicious versions designed to deceive LayerZero's verifier into confirming a fraudulent transaction. Meanwhile, the attackers launched a distributed denial-of-service attack on uncompromised external RPC nodes to force failover to the compromised ones. The attack's success was contingent upon Kelp's 1-of-1 verifier configuration, which LayerZero had recommended against in favor of a multi-verifier setup with redundancy. LayerZero has confirmed that the attack did not affect any other application on the protocol and has since taken steps to prevent similar incidents, including refusing to sign messages for applications running single-verifier setups. The exploit has significant implications for how DeFi prices LayerZero risk, as it was a configuration failure rather than a protocol-level bug that created the vulnerability. The Lazarus Group's involvement marks the second major exploit attributed to the group in 18 days, following the Drift Protocol exploit on April 1, highlighting the group's rapid adaptation of its tactics.