LayerZero Attributes $290 Million Exploit to Kelp's Security Setup, Links Attack to North Korea's Lazarus Group

LayerZero has assigned blame for the $290 million Kelp DAO exploit to Kelp's own security configuration, stating that the protocol's single-verifier setup, which LayerZero had warned against, was the primary cause of the vulnerability. The attack, attributed with preliminary confidence to North Korea's Lazarus Group and its TraderTraitor subunit, exploited a novel vector targeting the infrastructure layer. The attackers compromised two remote procedure call (RPC) nodes that LayerZero's verifier relied on, swapping the binary software with malicious versions designed to deceive LayerZero's verifier into confirming a fraudulent transaction. To maintain the attack's invisibility, the compromised nodes continued to report accurate data to other systems. The attackers also launched a distributed denial-of-service attack on uncompromised external RPC nodes, forcing a failover to the compromised ones. Once the failover was triggered, the compromised nodes confirmed a valid cross-chain message, resulting in the release of 116,500 rsETH to the attackers. The malicious node software then self-destructed, wiping binaries and local logs. LayerZero emphasizes that the attack only succeeded due to Kelp's single-verifier configuration, which ignored recommendations for a multi-verifier setup with redundancy. The company has confirmed that there was no contagion to other applications on the protocol and has since brought its verifier back online, announcing that it will no longer sign messages for applications running single-verifier configurations. This incident highlights the importance of security configurations in DeFi and the need for protocols to prioritize robust security measures to mitigate the risk of targeted attacks.