Massive $292 Million Exploit Hits Kelp DAO
A recent security breach has left Kelp DAO, a liquid restaking protocol, reeling after an attacker drained approximately $292 million from its cross-chain bridge. The incident occurred when the attacker manipulated the data feeding into the system, forcing it to rely on compromised inputs and approve transactions that never actually took place. This exploit has significant implications for the decentralized finance (DeFi) space, particularly for Aave, which has been affected by the hack. The attacker deposited a substantial amount of the stolen funds into Aave as collateral, borrowing around $190 million in ETH and related assets. To mitigate the risk, Aave Labs swiftly froze rsETH markets, set loan-to-value ratios to zero, and halted new borrowing against the asset. The outcome now largely depends on how Kelp handles the shortfall, with potential losses ranging from $124 million to $230 million. In related news, North Korea-linked hackers appear to be evolving their tactics, exploiting the basic assumptions built into decentralized systems rather than just looking for bugs or stolen credentials. Meanwhile, Coinbase has commissioned a report highlighting the potential risks of quantum computing to the crypto industry, emphasizing the need for preparation and caution. While current quantum machines are not powerful enough to crack the cryptography underpinning major networks, the report stresses that a future 'fault-tolerant quantum computer' could pose a significant threat, and preparation must begin now.