The $292 Million Kelp DAO Breach Exposes the Crypto Industry's Weakest Point: Bridges
The recent $292 million KelpDAO exploit highlights the ongoing issue of crypto bridge hacks, which have become a primary target for attackers due to their role in connecting blockchains. This incident involved KelpDAO's use of LayerZero's cross-chain messaging system, a widely used infrastructure for transferring data and assets between blockchains. Bridges are intended to facilitate the movement of assets between different blockchains, but they have repeatedly proven to be weak points, resulting in the loss of billions of dollars over the past few years. According to crypto ecosystem leaders, the problem is not solely due to poor coding or careless mistakes, but rather a fundamental issue with the way bridges are constructed. The core problem lies in the fact that bridges rely on intermediaries to verify transactions, rather than independently verifying the truth. This creates a risk, as attackers can compromise these intermediaries and feed false information into the system. Experts believe that bridge hacks are often symptoms of a deeper issue, with problems ranging from code vulnerabilities to centralization issues and social engineering. The process of using bridges appears simple to users, but it involves a complex series of steps, including locking tokens on the original blockchain, confirming the lock, and sending a message to the second blockchain to issue new tokens. However, this process relies on trusting the entity that sends the message, and if attackers compromise this entity, they can send false messages and create unbacked tokens. The industry's failure to address these issues is partly due to incentives, with security often taking a backseat to rapid launch and growth. Building secure systems requires time and resources, which many DeFi projects lack. Moreover, the complexity of bridge systems increases with each new integration, making them more vulnerable to attacks. To make bridges safer, experts recommend removing single points of failure by relying on independent data sources and implementing hardware protections and better monitoring. Some developers are also working on designs that verify data directly using cryptography, eliminating the need for intermediaries. Ultimately, a more fundamental shift in the design of bridges is necessary to address these issues and prevent future attacks.