Kelp DAO Suffers $292 Million Exploit: A Deep Dive into the Incident

A significant incident occurred over the weekend when a cross-chain bridge associated with Kelp DAO was drained of approximately $292 million worth of rsETH (restaked ether). This exploit, which accounted for about 18% of the total circulating supply of rsETH, was facilitated through LayerZero, a cross-chain messaging layer. An attacker manipulated the system by tricking it into believing a valid instruction had been received from another network, resulting in the release of 116,500 rsETH to an attacker-controlled address. Following the incident, Kelp DAO's emergency pauser multisig froze the protocol's core contracts to prevent further unauthorized transactions. The attack has raised concerns about the security of decentralized systems and the evolving strategies of hackers, including those linked to North Korea. In a related development, Aave has been affected by the Kelp DAO hack, with the attacker depositing a substantial amount of rsETH as collateral and borrowing approximately $190 million in ETH and related assets. Aave has taken measures to contain the risk, including freezing rsETH markets and halting new borrowing against the asset. Meanwhile, Coinbase has commissioned a report on the risks associated with quantum computing, emphasizing the need for the crypto industry to prepare for potential threats to encryption security.