Crypto Bridges Remain a Weak Point in the Industry: The $292 Million Kelp DAO Exploit Explained
The latest crypto bridge hack, resulting in a $292 million loss for KelpDAO, has once again exposed the weaknesses of these systems designed to connect blockchains. This exploit, like many before it, demonstrates how bridges have become a prime target for attackers. The incident involved KelpDAO's use of LayerZero's cross-chain messaging system, which is widely used to transfer data and assets between blockchains. However, instead of facilitating seamless transactions, bridges have repeatedly become the Achilles' heel of the crypto ecosystem, with billions of dollars lost over the past few years. According to crypto ecosystem leaders, the root cause of these vulnerabilities is not merely bad code or human error, but rather a fundamental flaw in the way bridges are constructed. The core issue lies in the trust placed in intermediaries, which can be compromised, allowing attackers to manipulate the system. To comprehend this problem, it is essential to understand the function of a bridge. When tokens are moved from one blockchain to another, the second chain requires proof that the tokens existed and were locked on the first chain. Ideally, this verification would be done independently, but in reality, it is often too complex and expensive. As a result, bridges rely on smaller systems to report this information, creating a single point of failure. In the case of the Kelp DAO-related exploit, attackers targeted the data feeding into the bridge, compromising nodes and feeding the system false information. This resulted in the bridge functioning as designed but believing incorrect data. Experts argue that bridge hacks often appear different on the surface but are symptoms of a deeper issue. The real problem lies in the design of these systems, which can be vulnerable to code vulnerabilities, centralization issues, social engineering, and economic attacks. The process of using a bridge may seem straightforward to users, but it involves a complex series of steps. First, tokens are locked on the original blockchain, and then a separate system confirms this lock. This system, typically consisting of a small group of operators or validators, sends a message to the second blockchain, which then creates a new version of the tokens. However, this process relies on trusting the entity sending the message. If attackers compromise this system, they can send false messages, creating tokens that were never backed on the original chain. The crypto industry has not yet addressed these vulnerabilities due to various factors, including incentives. Many DeFi projects prioritize launching quickly and growing their user base over investing in security. To make bridges safer, experts recommend removing single points of failure by relying on independent data sources rather than shared infrastructure. Other approaches include implementing hardware protections, improving monitoring, and designing systems that verify data directly using cryptography. Ultimately, a more fundamental shift is needed to address the weaknesses of crypto bridges. As long as the industry relies on validator-based bridges, these problems will persist.