Kelp DAO Suffers $292 Million Exploit

A recent incident has seen Kelp DAO, a liquid restaking protocol, drained of 116,500 rsETH, valued at approximately $292 million. The attacker exploited a vulnerability in LayerZero's cross-chain messaging layer, tricking the system into releasing the funds to an attacker-controlled address. Kelp DAO's emergency pauser multisig was able to freeze the protocol's core contracts 46 minutes after the attack, preventing further losses. However, the incident has raised concerns about the security of decentralized systems and the evolving tactics of North Korea-linked hackers. The attack on Kelp DAO is the second major exploit in recent weeks, following a similar incident at crypto trading firm Drift. Experts warn that these incidents are not isolated, but rather part of a larger, more organized effort by North Korea to hijack funds from the crypto sector. The Kelp DAO exploit has also had a ripple effect on other protocols, including Aave, which has been left exposed to collateral whose backing may be significantly impaired. In response, Aave Labs has taken steps to contain the risk, including freezing rsETH markets and halting new borrowing against the asset. Meanwhile, Coinbase has commissioned a report on the risks posed by quantum computing to the crypto industry. The report concludes that while current blockchains remain secure, the industry cannot afford to wait to prepare for the potential risks posed by future quantum computers.