‼️ The 47% Problem ‼️


Kelp DAO lost $292 million on Saturday.
No smart contract bug was found. Every contract involved had passed audits. The configuration that made it possible is the same one roughly half of LayerZero's integrations are still running this week.
🔓 What Happened
An attacker pre-funded wallets through Tornado Cash, then compromised two RPC nodes that LayerZero's Decentralised Verifier Network relied on to confirm cross-chain transactions.
The compromised nodes were swapped out for malicious versions that fed false data to the verifier while reporting accurate information to everything else, including LayerZero's own monitoring.
A simultaneous DDoS attack against the uncompromised RPCs forced failover onto the poisoned nodes.
With the verifier deceived, the attacker forged a cross-chain message claiming to originate from Kelp's U...
ZRO3.73%
post-image
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pin