Huge Loss for Kelp DAO: $292 Million Stolen in Exploit
Recent Developments in the Crypto Space KELP DAO BREACH: A significant cross-chain bridge, holding nearly a fifth of the circulating supply of a restaked ether token, was drained, causing rapid fallout in DeFi. An attacker exploited the bridge, withdrawing 116,500 rsETH (restaked ether) valued at approximately $292 million, which is roughly 18% of the token's circulating supply. This bridge, powered by LayerZero, enables different blockchains to send verified instructions to each other. Kelp DAO is a liquid restaking protocol that takes user-deposited ETH, earns additional yield through EigenLayer, and issues rsETH as a tradable receipt. The attacker manipulated LayerZero's cross-chain messaging layer into releasing 116,500 rsETH to an attacker-controlled address. Following the attack, Kelp's emergency pauser multisig froze the protocol's core contracts, and subsequent attempts to drain another 40,000 rsETH were reverted. — Shaurya Malwa Read more. NORTH KOREA'S CRYPTO ATTACKS: Less than three weeks after North Korea-linked hackers used social engineering to target crypto trading firm Drift, they seem to have carried out another major exploit on Kelp. This attack suggests an evolution in North Korea-linked hackers' tactics, as they now exploit basic assumptions in decentralized systems rather than just looking for bugs or stolen credentials. The combined incidents indicate a more organized effort by North Korea to hijack crypto funds. "This is not a series of incidents; it is a cadence," said Alexander Urbelis, chief information security officer and general counsel at ENS Labs. Over $500 million was siphoned in the Drift and Kelp exploits within two weeks. The Kelp exploit did not involve breaking encryption but rather manipulating data to force the system to rely on compromised inputs, leading to unauthorized transactions. — Margaux Nijkerk Read more. AAVE IMPACTED BY KELP DAO HACK: An attacker forged a valid transfer message, causing the system to approve a transfer that never occurred, resulting in 116,500 rsETH being released from the Ethereum-side bridge. Instead of selling the assets, the attacker deposited 89,567 rsETH into Aave as collateral and borrowed approximately $190 million in ETH and related assets. Aave Labs quickly responded to contain the risk by freezing rsETH markets, setting loan-to-value ratios to zero, and halting new borrowing against the asset. The outcome depends on how Kelp handles the shortfall. If losses are spread across all rsETH holders, Aave would face about $124 million in bad debt. If losses are isolated to Layer 2 networks, the impact would be more severe, with bad debt rising to roughly $230 million. — Margaux Nijkerk Read more. COINBASE REPORT ON QUANTUM COMPUTING RISKS: A report commissioned by Coinbase warns that while current blockchains are secure, the advent of a "fault-tolerant quantum computer" capable of breaking widely used encryption is increasingly plausible, and preparation must begin now. The report, authored by prominent cryptographers and academics, concludes that today's quantum machines are not powerful enough to crack the cryptography underpinning major crypto networks. However, breaking standard encryption would require significant computational overhead, a milestone still considered a major engineering challenge. The report stresses the need for the crypto industry to prepare for quantum risks. — Margaux Nijkerk Read more. Other News Regulatory and Policy Updates Calendar