The security threshold of the cross-chain bridge has been raised again; in the future, DVN will need to have several more redundant nodes.

DVN-2.66%
View Original
WuSaidBlockchainW
LayerZero discloses KelpDAO rsETH bridge attack incident, with North Korean hacker group identified as the mastermind.
LayerZero incident report states that on April 18, its cross-chain protocol-based KelpDAO rsETH bridge was attacked, resulting in a loss of approximately 116,500 rsETH (about $292 million).
The attack began on March 6, with the attacker obtaining the developer session key through social engineering, infiltrating the RPC cloud environment, and contaminating internal nodes.
Subsequently, a DoS attack was launched against external RPC providers, forcing the DVN signing service to rely only on two compromised internal nodes, thereby providing an effective proof for forging cross-chain messages.
LayerZero indicated that the incident originated from the configuration of a single validator in the related OApp, and did not affect other OApps, channels, or transactions.
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pinned