Kelp DAO Suffers $292 Million Exploit: A Major Setback for the Crypto Space
A significant breach occurred in the Kelp DAO, a liquid restaking protocol, resulting in the loss of $292 million. This incident happened when an attacker manipulated the cross-chain messaging layer, LayerZero, to trick the Kelp DAO's bridge into releasing 116,500 rsETH to an attacker-controlled address. The emergency pauser multisig froze the protocol's core contracts 46 minutes after the successful drain, but not before two follow-up attempts were made to drain an additional 40,000 rsETH. Experts believe that North Korea-linked hackers are behind the attack, demonstrating an evolution in their tactics by exploiting the basic assumptions built into decentralized systems. The attack on Kelp DAO did not involve breaking encryption or cracking keys but rather manipulating the data feeding into the system, causing it to approve transactions that never actually occurred. The fallout from this exploit has affected Aave, which has frozen rsETH markets and set loan-to-value ratios to zero to contain the risk. The outcome depends largely on how Kelp handles the shortfall, with potential losses ranging from $124 million to $230 million. In other news, Coinbase has commissioned a report on the risks of quantum computing, emphasizing that while current blockchains remain secure, the industry cannot afford to wait to prepare for the potential threats posed by future 'fault-tolerant quantum computers.'