SlowMist Cosine: Kelp attackers use single-signature configuration, fees come from Tornado Cash

ME News Report, April 19 (UTC+8), regarding the Kelp theft of 116,500 rsETH, according to initial analysis by SlowMist's Yuán Cí: The LayerZero cross-chain used by the attacker is a 1/1 DVN configuration, which is the classic "single signature" setup, whereas the LayerZero official documentation defaults to a 2/2 configuration. This "single signature single point" may have also been compromised through social engineering (just a guess, details pending investigation). The attacker successfully stole 116,500 rsETH on Ethereum, and actually attempted two more times to steal 40k rsETH but failed; the attacker's transaction fees came from Tornado Cash. The 116,500 rsETH was washed through multiple addresses, shifting the pressure onto various staking platforms, especially Aave, which now faces huge bad debts. (Source: PANews)
ZRO-4.62%
ETH-3.75%
AAVE-6.71%
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • 4
  • Repost
  • Share
Comment
Add a comment
Add a comment
DegenLibrarian
· 5h ago
The official is clearly pushing 2/2, but the project team insists on skimping on gas and doing it with a single signature—so they ended up paying tuition the hard way… and somehow it’s still “爽.”
View OriginalReply0
ViewingBullAndBearMarketsFromA
· 5h ago
Attempted to push again twice for 40k but failed; on-chain risk control still has an effect.
View OriginalReply0
GateUser-8d51653b
· 5h ago
116k rsETH, “decentralized washing” — aren’t staking platforms feeling pretty stressed right now?
View OriginalReply0
BridgeBurner
· 5h ago
Tornado Cash exits the stage, a veteran performer.
View OriginalReply0
  • Pinned