LayerZero admet une erreur dans l'exploitation de 292 millions de dollars chez Kelp

LayerZero a reconnu avoir commis une erreur en autorisant son propre réseau de vérification à sécuriser des actifs de grande valeur dans une configuration vulnérable. Cet aveu survient quelques semaines après un piratage de 292 millions de dollars chez Kelp DAO, que l'entreprise avait initialement attribué au développeur. La société affirme que son protocole principal est resté intact.

LayerZero a déclaré vendredi dernier avoir commis une erreur en permettant à son réseau de vérification décentralisé de fonctionner dans une configuration 1-sur-1 pour les transferts de grande valeur. Cette configuration a créé un point de défaillance unique que les attaquants ont exploité en avril. L'entreprise a attribué la brèche à une attaque contre son infrastructure RPC interne, tandis que des fournisseurs externes ont fait face simultanément à des tentatives de déni de service distribué.

Articles connexes

Dramatic courtroom scene depicting lawyers arguing over frozen Ethereum coins from Kelp DAO hack amid terrorism claims.
Image générée par IA

Aave fights to unfreeze $71 million amid Kelp DAO hack court battle

Rapporté par l'IA Image générée par IA

A federal case is unfolding over $71 million in frozen cryptocurrency following the Kelp DAO exploit, as Aave seeks to release the funds for DeFi recovery. Victims of decades-old North Korean terrorist acts have filed a restraining notice against Arbitrum DAO, claiming the 30,765 ETH as DPRK-linked property. The dispute pits recent hack victims against long-standing terrorism judgment holders.

Kelp DAO has accused LayerZero personnel of approving the 1-of-1 verifier setup blamed for a $292 million exploit on its rsETH bridge. The protocol plans to migrate from LayerZero's OFT standard to Chainlink's CCIP. The hack has been linked to North Korea's Lazarus Group.

Rapporté par l'IA

A $292 million exploit on Kelp DAO has shaken decentralized finance (DeFi) lending markets, prompting industry insiders to call for stronger security measures. Despite the setback, experts view it as a temporary hurdle rather than a barrier to institutional adoption. Wall Street firms continue advancing into onchain finance amid the fallout.

Humanity Protocol said hackers stole more than $36 million in H tokens by compromising an employee's laptop that held multiple bridge admin keys. The decentralized identity project has halted bridge activity and is working with law enforcement.

Rapporté par l'IA

SecondFi, the Cardano wallet formerly known as Yoroi, confirmed losses of 16 million ADA worth about 2.4 million dollars from 374 user wallets in three attacks. The firm secured an additional 129 million ADA before further drains occurred. A flaw in its proprietary wallet generation software caused the breach.

European stablecoin issuer StablR has frozen operations for its USDR and EURR tokens following a cyberattack that left the assets under-collateralized.

Rapporté par l'IA

Zcash has recovered about 45 percent from its recent low after developers proposed the Ironwood upgrade to address a supply verification issue. The privacy-focused cryptocurrency traded near $437 on Monday, though it remains down 22 percent for the week. The move comes after a patched bug in the Orchard pool triggered last week's sell-off.

 

 

 

Ce site utilise des cookies

Nous utilisons des cookies pour l'analyse afin d'améliorer notre site. Lisez notre politique de confidentialité pour plus d'informations.
Refuser