LayerZero Points to Kelp's Security Setup as Cause of $290 Million Exploit, Links Attack to North Korea's Lazarus Group
LayerZero has attributed the $290 million Kelp DAO exploit to a security configuration flaw in Kelp's setup, specifically the use of a single-verifier configuration despite recommendations for a multi-verifier approach. The attack, which LayerZero believes with preliminary confidence was carried out by North Korea's Lazarus Group, involved compromising two remote procedure call (RPC) nodes that LayerZero's verifier relied on for cross-chain transactions. These nodes were manipulated to report false transaction data to LayerZero's verifier while providing accurate data to other systems, effectively hiding the attack from LayerZero's monitoring. To ensure the attack's success, the perpetrators also launched a distributed denial-of-service (DDoS) attack on uncompromised external RPC nodes, forcing a failover to the compromised nodes. This DDoS attack occurred between 10:20 a.m. and 11:40 a.m. Pacific Time on Saturday, according to traffic logs shared by LayerZero. Once the failover was triggered, the compromised nodes falsely confirmed a cross-chain message, resulting in Kelp's bridge releasing 116,500 rsETH to the attackers. The malicious software then self-destructed, eliminating binaries and local logs. The exploit was only possible due to Kelp's 1-of-1 verifier configuration, where LayerZero Labs was the sole verifier of messages to and from the rsETH bridge. LayerZero had recommended a multi-verifier setup with redundancy, which would have required consensus across several independent verifiers to confirm a message, thereby preventing the attack. LayerZero has confirmed that there was no contagion to other applications on the protocol, with all OFT-standard tokens and applications using multi-verifier setups remaining unaffected. The LayerZero Labs verifier is now back online, and the company has announced it will no longer support applications with single-verifier configurations, effectively mandating a protocol-wide migration to multi-verifier setups. This distinction is crucial for how DeFi assesses LayerZero risk moving forward, as it differentiates between a protocol-level bug and a configuration failure by an integrator. The attack highlights the adaptability of the Lazarus Group, which has been linked to the Drift Protocol exploit on April 1 and now the Kelp exploit on April 18, resulting in the drainage of over $575 million from DeFi in just 18 days through two distinct attack vectors.