KelpDAO bridge vulnerability exploited, $292M in rsETH drained in single-verifier attack

1 hour ago 2



A cross-chain bridge adapter used by KelpDAO was exploited for approximately $292 million in rsETH on April 18, after attackers found a way to abuse what turned out to be a catastrophically simple weakness: the entire system relied on a single verifier to authenticate transactions. The breach drained 116,500 rsETH from KelpDAO’s LayerZero-powered Omnichain Fungible Token (OFT) adapter on Ethereum, representing roughly 18% of the token’s circulating supply. The fallout was swift and brutal, with more than $10 billion in withdrawals cascading across DeFi protocols in the hours that followed. How one validator became a $292M liability KelpDAO’s bridge adapter was configured with what’s known as a 1-of-1 Decentralized Verifier Network, or DVN. The attackers forged a message claiming that a corresponding burn of rsETH had occurred on Unichain. Because only one validator, operated by LayerZero Labs, needed to sign off on the transaction’s legitimacy, the forged message was all it took. The DVN attested to a transaction that never actually happened, and the Ethereum-side adapter dutifully released the reserves. The attack vector wasn’t a smart contract bug in the traditional sense. Instea...

Read Entire Article