The $292 Million Kelp DAO Breach Highlights the Vulnerability of Crypto Bridges
A recent $292 million exploit linked to KelpDAO has brought attention to the ongoing issue of crypto bridge hacks, which have become a common vulnerability in the blockchain ecosystem. The incident involved KelpDAO's use of LayerZero's cross-chain messaging system, a widely used infrastructure for transferring data and assets between blockchains. However, instead of facilitating seamless transactions, bridges have repeatedly been exploited, resulting in the loss of billions of dollars over the past few years. According to crypto ecosystem leaders, the problem is not solely due to poor coding or careless mistakes, but rather a fundamental flaw in the way bridges are constructed. At the core of the issue is the reliance on intermediaries to verify transactions, rather than implementing a more secure and decentralized approach. Most bridges do not fully verify transactions on other chains, instead relying on smaller systems to report the information, which creates a single point of failure. This shortcut can be exploited by attackers, as seen in the Kelp DAO-related breach, where attackers compromised nodes and fed the system false information. Experts argue that bridge hacks are often symptoms of a deeper issue, with code vulnerabilities, centralization, social engineering, and economic attacks all contributing to the problem. The process of using bridges appears simple to users, but behind the scenes, it involves a complex series of steps, including locking tokens on the original blockchain, confirming the lock, and sending a message to the second blockchain to issue new tokens. However, this process relies on trusting the system that sends the message, which can be compromised by attackers. The industry has yet to fix the issue due to a lack of incentives, with security often taking a backseat to rapid development and user growth. Many DeFi projects operate with limited resources, making it difficult to invest in audits, monitoring, and infrastructure. As the industry continues to expand, with more blockchains being supported, the complexity of bridges increases, adding more assumptions and potential vulnerabilities. Bridge hacks can have far-reaching consequences, with compromised assets being used across multiple platforms, leading to contagion. To make bridges safer, experts recommend removing single points of failure by relying on independent data sources, implementing hardware protections, and improving monitoring. Some developers are also exploring new designs that verify data directly using cryptography, rather than relying on intermediaries. Ultimately, a more fundamental shift in the way bridges are designed and constructed is necessary to address the ongoing issue of crypto bridge hacks.