Kelp DAO Suffers $292 Million Exploit: A New Wave of DeFi Attacks
A significant exploit has occurred in the DeFi space, with Kelp DAO, a liquid restaking protocol, being drained of approximately $292 million. This incident involved a cross-chain bridge holding nearly a fifth of the circulating supply of restaked ether tokens. An attacker manipulated the system by tricking LayerZero's cross-chain messaging layer into releasing 116,500 rsETH to an attacker-controlled address. The emergency pauser multisig froze the protocol's core contracts 46 minutes after the successful drain, preventing further attacks. However, this incident highlights the evolving nature of threats in the DeFi space, particularly with the involvement of North Korea-linked hackers. These hackers have been using sophisticated tactics, including social engineering and exploiting the basic assumptions built into decentralized systems. The attack on Kelp DAO suggests an evolution in their methods, focusing on manipulating data feeding into systems rather than breaking encryption or cracking keys. This approach allowed them to force the system to approve transactions that never actually occurred. The fallout from this exploit is significant, with Aave being affected as the attacker deposited a large portion of the stolen rsETH as collateral and borrowed roughly $190 million in ETH and related assets. Aave Labs has taken steps to contain the risk, including freezing rsETH markets and halting new borrowing against the asset. The outcome depends largely on how Kelp handles the shortfall, with potential impacts on the value of the staked tokens and bad debt for Aave. In a related development, Coinbase has commissioned a report on the risks of quantum computing to the crypto industry. While current quantum machines are not powerful enough to crack the cryptography underpinning major networks, the report stresses the need for preparation and the development of quantum-resistant technologies to ensure the long-term security of the crypto sector.