LayerZero Attributes $290 Million Kelp Exploit to Inadequate Security Setup and North Korea's Lazarus Group

LayerZero has attributed the recent $290 million exploit of Kelp DAO to a security configuration flaw on Kelp's part, specifically the use of a single-verifier setup despite previous warnings against such a configuration. The exploit, which LayerZero believes with preliminary confidence was carried out by North Korea's Lazarus Group, involved the compromise of two remote procedure call (RPC) nodes that LayerZero's verifier relied on. These nodes were manipulated to report false transaction data to LayerZero's verifier while maintaining accurate data for other systems, thus avoiding detection by LayerZero's monitoring infrastructure. To ensure the attack's success, the attackers also launched a distributed denial-of-service (DDoS) attack on uncompromised external RPC nodes, forcing a failover to the compromised nodes. This led to the release of 116,500 rsETH to the attackers. The attack's success is attributed to Kelp's failure to implement a multi-verifier setup with redundancy, a configuration that LayerZero had recommended to prevent such vulnerabilities. The incident highlights the importance of robust security configurations in preventing exploits and the evolving nature of threats in the DeFi space, particularly from sophisticated groups like Lazarus.