KelpDAO Suffers $292M Exploit Due to Single Verifier Vulnerability
A major security breach occurred on April 18, when KelpDAO's cross-chain bridge adapter was exploited, resulting in the loss of around $292 million in rsETH. The attack was facilitated by a critical flaw in the system, which relied on a single verifier for transaction authentication.
The exploit drained 116,500 rsETH from KelpDAO’s LayerZero-powered Omnichain Fungible Token (OFT) adapter on Ethereum, accounting for about 18% of the token's circulating supply. Following the breach, over $10 billion in withdrawals cascaded across various DeFi protocols.
Details of the Attack
The attackers utilized a 1-of-1 Decentralized Verifier Network (DVN) configuration, allowing them to forge a message that falsely claimed a corresponding burn of rsETH had occurred on Unichain. Since only one validator, operated by LayerZero Labs, was required to authenticate the transaction, the forged message was sufficient to release the reserves.
Rather than exploiting a traditional smart contract bug, the attackers compromised LayerZero’s internal RPC nodes, substituting legitimate binaries with counterfeit versions to mislead the sole DVN. To prevent any backup systems from intervening, they simultaneously launched a DDoS attack against external nodes, forcing the system into a failover state.
KelpDAO's emergency multisignature team managed to pause the core contracts approximately 46 minutes after the attack began, preventing further losses of an additional 40,000 rsETH.
Connection to Lazarus Group
Preliminary investigations have linked the attack to North Korea’s Lazarus Group, particularly its TraderTraitor subgroup. The complexity of the attack, which combined supply chain compromise with a coordinated DDoS campaign, aligns with the group's known tactics. So far, recovery efforts have managed to reclaim approximately $71 million, roughly a quarter of the funds stolen.
Impact on DeFi Protocols
The incident has prompted a significant reassessment of DVN configurations among protocols utilizing LayerZero’s OFT standard. A more secure 2-of-3 or 3-of-5 DVN setup would have posed a greater challenge for attackers, as it would require compromising multiple independent validators simultaneously.
For investors, this incident serves as a stark reminder to evaluate the security measures in place for any protocol relying on cross-chain messaging, particularly the number of validators involved in transaction verification.
FAQ
What happened during the KelpDAO exploit?
On April 18, KelpDAO's cross-chain bridge adapter was exploited due to a vulnerability that relied on a single verifier for transaction authentication, resulting in the loss of approximately $292 million in rsETH.
How did the attackers exploit the KelpDAO system?
The attackers used a 1-of-1 Decentralized Verifier Network (DVN) configuration to forge a message that falsely claimed a burn of rsETH had occurred on Unichain. They compromised LayerZero’s internal RPC nodes and launched a DDoS attack to prevent backup systems from intervening.
What is the connection between the KelpDAO attack and the Lazarus Group?
Preliminary investigations suggest that the attack is linked to North Korea’s Lazarus Group, specifically its TraderTraitor subgroup, due to the complexity and tactics used in the attack.
What measures are being taken to recover the stolen funds?
Recovery efforts have managed to reclaim approximately $71 million, which is about a quarter of the funds stolen during the exploit.
What implications does this incident have for DeFi protocols?
The incident has prompted a reassessment of DVN configurations among protocols using LayerZero’s OFT standard, highlighting the need for more secure setups, such as 2-of-3 or 3-of-5 DVN configurations, to enhance security against similar attacks.
Comments
Comments are moderated before publish.
No comments yet — be the first.