Kelp DAO Suffers $292 Million Exploit
Recent Developments in Crypto KELP DAO BREACH: A significant cross-chain bridge holding nearly 18% of the total circulating supply of a restaked ether token has been drained. The aftermath is spreading rapidly through DeFi, outpacing Kelp DAO's efforts to pause contracts. Over the weekend, at 17:35 UTC, an attacker withdrew 116,500 rsETH (restaked ether), valued at approximately $292 million, from Kelp DAO's LayerZero-powered bridge. This represents about 18% of the rsETH's total circulating supply of 630,000 tokens tracked by CoinGecko. LayerZero acts as a cross-chain messaging layer, enabling different blockchains to send verified instructions to one another. Kelp DAO is a liquid restaking protocol that takes user-deposited ETH, channels it through EigenLayer to earn additional yield beyond standard Ethereum staking rewards, and issues rsETH as a tradable receipt. The drained bridge held the rsETH reserve backing wrapped versions of the token on over 20 other blockchains. The attacker deceived LayerZero's cross-chain messaging layer into believing a valid instruction had been received from another network, prompting Kelp's bridge to release 116,500 rsETH to an attacker-controlled address. Kelp's emergency pauser multisig froze the protocol's core contracts 46 minutes after the successful drain, at 18:21 UTC. Two subsequent attempts at 18:26 UTC and 18:28 UTC were reverted, each carrying the same LayerZero packet in an attempt to drain another 40,000 rsETH worth roughly $100 million. NORTH KOREA'S CRYPTO ATTACK PLAYBOOK: Less than three weeks after North Korea-linked hackers used social engineering to target crypto trading firm Drift, hackers tied to the nation appear to have executed another major exploit on Kelp. The attack on Kelp, a restaking protocol integrated into LayerZero's cross-chain infrastructure, suggests an evolution in the tactics of North Korea-linked hackers, who are now exploiting the fundamental assumptions built into decentralized systems, rather than just seeking bugs or stolen credentials. The two incidents collectively point to a more organized effort by North Korea to hijack crypto sector funds, with over $500 million siphoned off in just over two weeks. At its core, the Kelp exploit did not involve breaking encryption or cracking keys; instead, attackers manipulated the data feeding into the system, forcing it to rely on compromised inputs and approve transactions that never occurred. AAVE IMPACTED BY KELP DAO HACK: An attacker exploited the setup by forging a transfer message that appeared valid, causing the system to approve the transfer even though the tokens were never removed from the sending chain, effectively creating new tokens without backing. The attacker deposited 89,567 rsETH into Aave as collateral and borrowed approximately $190 million in ETH and related assets across Ethereum and Arbitrum. Aave Labs moved quickly to contain the risk, freezing rsETH markets, setting loan-to-value ratios to zero, and halting new borrowing against the asset. The outcome now largely depends on how Kelp handles the shortfall. If losses are spread across all rsETH holders, the token could face an estimated 15% depegging, resulting in about $124 million in bad debt for Aave. If losses are instead isolated to Layer 2 networks, the impact would be more severe, with bad debt rising to roughly $230 million. COINBASE REPORT ON QUANTUM COMPUTING RISKS: A report commissioned by Coinbase highlights the need for caution and urgency regarding quantum computing risks. While current blockchains remain secure, the possibility of a future 'fault-tolerant quantum computer' capable of breaking widely used encryption is increasingly plausible, and preparation must begin now. Recent months have seen concerns around quantum risk move into the mainstream, with Google researchers estimating that a sufficiently advanced quantum computer could break Bitcoin's cryptography. Major crypto ecosystems have started mapping out their responses, with the Ethereum Foundation proposing new digital signatures designed to be safe against quantum computers, and Solana experimenting with quantum-resistant wallet designs.