Internal nodes are compromised + external RPC is DoSed, the attack and defense are asymmetric.

View Original
WuSaidBlockchainW
LayerZero discloses KelpDAO rsETH bridge attack incident, with North Korean hacker group identified as the mastermind.
LayerZero incident report states that on April 18, its cross-chain protocol-based KelpDAO rsETH bridge was attacked, resulting in a loss of approximately 116,500 rsETH (about $292 million).
The attack began on March 6, with the attacker obtaining the developer session key through social engineering, infiltrating the RPC cloud environment, and contaminating internal nodes.
Subsequently, a DoS attack was launched against external RPC providers, forcing the DVN signing service to rely only on two compromised internal nodes, thereby providing an effective proof for forging cross-chain messages.
LayerZero indicated that the incident originated from the configuration of a single validator in the related OApp, and did not affect other OApps, channels, or transactions.
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pinned