LayerZero Attributes $290 Million Kelp DAO Exploit to Inadequate Security Setup and North Korea's Lazarus Group
LayerZero has assigned blame for the $290 million Kelp DAO exploit to Kelp's security configuration, stating that the protocol's single-verifier setup, which LayerZero had previously advised against, was the primary factor. The attack, attributed with preliminary confidence to North Korea's Lazarus Group and its TraderTraitor subunit, involved compromising two remote procedure call (RPC) nodes that LayerZero's verifier relied on for cross-chain transaction verification. These nodes were manipulated to report false data to LayerZero's verifier while maintaining accurate data for other systems, thus remaining undetected by LayerZero's monitoring infrastructure. To ensure the attack's success, the perpetrators also launched a distributed denial-of-service attack on uncompromised external RPC nodes, forcing a failover to the compromised nodes. This led to the release of 116,500 rsETH to the attackers. The attack's success can be attributed to Kelp's 1-of-1 verifier configuration, contrary to LayerZero's recommendations for a multi-verifier setup with redundancy. LayerZero has confirmed that the attack did not affect any other applications on the protocol and has since taken the LayerZero Labs verifier offline for applications running single-verifier configurations, prompting a protocol-wide migration to multi-verifier setups. The distinction between a protocol-level bug and a configuration failure is significant for how DeFi prices LayerZero risk. Meanwhile, the Lazarus Group has been linked to over $575 million in DeFi exploits in 18 days, adapting its tactics faster than DeFi protocols can bolster their defenses.