Major Exploit: Kelp DAO Loses $292 Million in Cross-Chain Heist

A significant exploit has occurred in the Kelp DAO, a liquid restaking protocol, resulting in the loss of approximately $292 million. The breach happened when an attacker tricked LayerZero's cross-chain messaging layer into releasing 116,500 rsETH to an attacker-controlled address. The Kelp DAO's emergency pauser multisig froze the protocol's core contracts 46 minutes after the successful drain. This incident is believed to be linked to North Korea, which has been escalating its efforts to hijack funds from the crypto sector. The attack on Kelp suggests an evolution in the tactics used by North Korea-linked hackers, who are now exploiting the basic assumptions built into decentralized systems. The exploit did not involve breaking encryption but rather manipulating the data feeding into the system, causing it to approve transactions that never actually occurred. Aave, a lending protocol, has been affected by the Kelp DAO hack, with the attacker depositing 89,567 rsETH into Aave as collateral and borrowing roughly $190 million in ETH and related assets. Aave has taken steps to contain the risk, including freezing rsETH markets and halting new borrowing against the asset. In related news, Coinbase has commissioned a report on the risks of quantum computing to the crypto industry. The report concludes that while current blockchains remain secure, the industry cannot afford to wait to prepare for the potential risks of quantum computing. It stresses that current quantum machines are not powerful enough to crack the cryptography underpinning major crypto networks but notes that a future 'fault-tolerant quantum computer' capable of breaking widely used encryption is increasingly plausible.