LayerZero Says Kelp Switched rsETH Bridge to 1-of-1 Verification Before $292M Exploit

LayerZero said KelpDAO changed the rsETH bridge from a 2-of-2 DVN stack to a 1-of-1 setup before the April 18 exploit that released 116,500 rsETH worth about $292 million. LayerZero said the breach began on March 6 after malware on a developer's Mac gave the attacker access to internal RPC infrastructure for six weeks. On April 18, LayerZero said tampered op-geth servers and DDoS attacks on external RPC providers helped produce a forged attestation that unlocked the funds. Mandiant and CrowdStrike attributed the operation with high confidence to UNC4899, a DPRK-linked group.
ZRO-0.72%
OP3.16%
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pinned