Kelp DAO Breach: $292 Million Stolen in Cross-Chain Exploit

Recent News A significant breach occurred in the Kelp DAO, a liquid restaking protocol, resulting in the theft of approximately $292 million. The attack exploited a cross-chain bridge, draining 116,500 rsETH (restaked ether) tokens. The bridge, powered by LayerZero, was tricked into releasing the tokens to an attacker-controlled address. The Kelp DAO's emergency pauser multisig froze the protocol's core contracts 46 minutes after the attack. Two subsequent attempts to drain an additional 40,000 rsETH were reverted. North Korean hackers have been linked to the Kelp DAO exploit, marking an evolution in their tactics. Rather than relying on bugs or stolen credentials, they manipulated the system's inputs, forcing it to approve fake transactions. This incident, combined with a recent attack on the crypto trading firm Drift, suggests a more organized effort by North Korean hackers to target the crypto sector. Over $500 million has been stolen in these two incidents alone. The Kelp DAO hack has also affected Aave, a lending protocol. The attacker deposited 89,567 rsETH into Aave as collateral and borrowed approximately $190 million in ETH and related assets. Aave has since frozen rsETH markets and set loan-to-value ratios to zero to contain the risk. The outcome depends on how Kelp DAO handles the shortfall, with potential losses ranging from $124 million to $230 million. Coinbase has commissioned a report on the risks of quantum computing to the crypto industry. While current blockchains are secure, the report warns that a future 'fault-tolerant quantum computer' could potentially break widely used encryption. The report stresses the need for preparation and highlights efforts by major crypto ecosystems to develop quantum-resistant technologies. Other News Regulatory and Policy Updates