KelpDAO Hack Exposes Vulnerability in Cross-Chain Bridges
KelpDAO's cross-chain bridge was exploited on April 18 due to a critical vulnerability. The attackers targeted a single verifier that authenticated transactions, allowing them to forge transaction messages and drain 116,500 rsETH (about $292 million). This breach also led to over $10 billion in DeFi withdrawals across protocols.
The incident has been linked to North Korea's Lazarus Group, which compromised LayerZero's internal nodes and carried out a DDoS attack to isolate the system. A partial recovery of $71 million has been made, but the incident highlights the risks of single-verifier setups in cross-chain bridges. Experts are now calling for multi-verifier configurations to improve security.
The breach also led to a significant drop in DeFi activity, with many users withdrawing their funds from affected protocols. This has raised concerns about the stability and security of DeFi systems, which are still in the early stages of development.