LayerZero's single-signature setup is to blame; the security model of cross-chain bridges needs to be re-evaluated.

ZRO-2.02%
View Original
MeNews
SlowMist Cosine: Kelp attackers use single-signature configuration, fees come from Tornado Cash
ME News reports that the initial analysis of the Kelp theft incident suggests that the attacker exploited LayerZero's single-signature 1/1 DVN configuration (which contradicts the official 2/2 recommendation), suspected to be influenced by social engineering. The attack stole 116,500 rsETH on Ethereum and previously attempted to steal 40,000 rsETH but failed, with transaction fees coming from Tornado Cash. The funds were dispersed and laundered, with the pressure transmitted to staking platforms, especially causing massive bad debt on Aave.
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments