LayerZero Attributes $290 Million Exploit to Kelp's Security Setup and North Korea's Lazarus Group

LayerZero has attributed the responsibility for the $290 million Kelp DAO exploit to Kelp's security configuration, specifically its use of a single-verifier setup despite LayerZero's recommendations for a multi-verifier setup. The attack, which LayerZero believes with preliminary confidence was carried out by North Korea's Lazarus Group and its TraderTraitor subunit, involved compromising two remote procedure call (RPC) nodes used by LayerZero's verifier to confirm cross-chain transactions. The attackers replaced the binary software on these nodes with malicious versions designed to deceive LayerZero's verifier into accepting a fraudulent transaction while appearing legitimate to other systems. To ensure the success of the attack, the perpetrators also launched a distributed denial-of-service (DDoS) attack on uncompromised external RPC nodes, forcing a failover to the compromised nodes. Once the failover was triggered, the compromised nodes informed the verifier that a valid cross-chain message had been received, resulting in the release of 116,500 rsETH to the attackers. The malicious software then self-destructed, eliminating any local logs or binaries. LayerZero emphasizes that the attack was only successful because Kelp had chosen to use a 1-of-1 verifier configuration, contrary to LayerZero's public integration checklist and direct communications recommending a multi-verifier setup for enhanced security. This configuration would have required consensus across multiple independent verifiers to confirm a message, thereby preventing the attack. LayerZero has confirmed that there has been no contagion to any other application on the protocol, with all OFT-standard tokens and applications using multi-verifier setups remaining unaffected. In response to the incident, LayerZero Labs has brought its verifier back online and announced that it will no longer sign messages for applications using single-verifier configurations, effectively necessitating a protocol-wide migration to multi-verifier setups. This distinction is significant for how DeFi prices LayerZero risk, as it indicates that the protocol functioned as intended, and the vulnerability was a result of Kelp's security choices rather than a flaw in LayerZero's code. The attack has been linked to the Lazarus Group, which has been implicated in the Drift Protocol exploit on April 1, resulting in the group draining over $575 million from DeFi in just 18 days through two distinct attack vectors.