The KelpDAO bridge hack, linked to North Korea's Lazarus Group, exploited a vulnerability in the Omnichain Fungible Token bridge, resulting in the theft of approximately 116,500 rsETH, valued at nearly $292 million. The attack highlighted a critical flaw in LayerZero's single-validator architecture, which critics argue poses a significant risk as a single point of failure. LayerZero has since acknowledged communication lapses and confirmed it will no longer offer 1-to-1 Data Verification Network (DVN) configurations, transitioning to more robust settings.
Following the breach, KelpDAO migrated to Chainlink's Cross-Chain Interoperability Protocol (CCIP), addressing the architectural vulnerability. This move has prompted other protocols, with a total locked value of around $2 billion, to follow suit. Meanwhile, DeFi United, formed by Aave, KelpDAO, and LayerZero, is working to restore collateral backing for rsETH, raising over $300 million in cryptocurrency. LayerZero has also enhanced its security measures, including a custom multi-signature system and increased signature thresholds.
KelpDAO Bridge Hack Exposes LayerZero's Single Validator Flaw
면책 조항: Phemex 뉴스에서 제공하는 콘텐츠는 정보 제공 목적으로만 제공됩니다. 제3자 기사에서 출처를 얻은 정보의 품질, 정확성 또는 완전성을 보장하지 않습니다.이 페이지의 콘텐츠는 재무 또는 투자 조언이 아닙니다.투자 결정을 내리기 전에 반드시 스스로 조사하고 자격을 갖춘 재무 전문가와 상담하시기 바랍니다.
