The Vulnerability of Crypto Bridges Exposed: $292 Million Kelp DAO Exploit Highlights Industry Weakness
The recent $292 million KelpDAO exploit has once again highlighted the weakness of crypto bridges, which are designed to connect different blockchains but have become a common target for hackers. This incident involved the use of LayerZero's cross-chain messaging system, a type of infrastructure widely used to move data and assets between blockchains. However, instead of providing a seamless connection, bridges have repeatedly become the weakest link in the chain, resulting in the loss of billions of dollars over the past few years. The problem lies in the fundamental design of bridges, which rely on trusting a middleman to verify the existence and locking of tokens on the original blockchain. This trust is often misplaced, as bridges outsource the verification process to smaller systems or external networks, creating a risk of compromise. Experts argue that the issue is not just a matter of bad code or careless mistakes, but rather a deeper problem with the way bridges are built. The core issue is the reliance on a trusted intermediary, which can be compromised by attackers. In the case of the Kelp DAO-related exploit, attackers targeted the data feeding into the bridge, compromising nodes and feeding the system false information. Bridge hacks often appear different on the surface, but experts say they are symptoms of a deeper issue. The real problem lies in the design of the systems, which can be vulnerable to code vulnerabilities, centralization issues, social engineering, and economic attacks. For users, bridges appear simple, but the process is more complicated. Tokens are locked on the original blockchain, and a separate system confirms the locking. However, this process depends on trusting the system that sends the message, which can be compromised by attackers. The industry has not fixed the issue due to incentives, with security often not being the top priority. Teams focus on launching quickly, growing users, and increasing total value locked, rather than investing in audits, monitoring, and infrastructure. Building secure systems takes time and money, and many DeFi projects operate with limited resources. The problem is exacerbated by the fact that projects are racing to support more blockchains, adding complexity and assumptions. Bridge hacks can have far-reaching consequences, as compromised assets are used across lending protocols, liquidity pools, and yield strategies. Experts argue that there are ways to make bridges safer, such as removing single points of failure and relying on independent data sources. However, many rely on the same underlying services, meaning a single compromised source can feed bad data across multiple systems. Other approaches include hardware protections and better monitoring to catch misconfigurations early. Some developers are working on designs that verify data directly using cryptography instead of intermediaries. Ultimately, a more fundamental shift is needed to address the issue of crypto bridge vulnerabilities.