Kelp DAO Suffers $292 Million Exploit
A significant incident has occurred in the crypto space, with Kelp DAO, a liquid restaking protocol, being drained of approximately $292 million. This event involved an attacker exploiting a cross-chain bridge, resulting in the theft of 116,500 rsETH (restaked ether) tokens. The attacker manipulated the system by tricking LayerZero's cross-chain messaging layer into releasing the tokens to an attacker-controlled address. Following the incident, Kelp DAO's emergency pauser multisig froze the protocol's core contracts to prevent further damage. The attack is suspected to be linked to North Korea, indicating an evolution in the nation's hacking strategies. The exploit has also affected Aave, with the attacker depositing the stolen rsETH as collateral and borrowing approximately $190 million in ETH and related assets. In response, Aave Labs has taken measures to contain the risk, including freezing rsETH markets and halting new borrowing against the asset. Meanwhile, Coinbase has commissioned a report on the risks of quantum computing to the crypto industry, emphasizing the need for preparation against potential future threats to encryption security.