Close Menu
    Facebook X (Twitter) Instagram
    • Privacy Policy
    • Terms Of Service
    • Social Media Disclaimer
    • DMCA Compliance
    • Anti-Spam Policy
    Facebook X (Twitter) Instagram
    Bytecore News
    • Home
    • Crypto News
      • Bitcoin
      • Ethereum
      • Altcoins
      • Blockchain
      • DeFi
    • AI News
    • Stock News
    • Learn
      • AI for Beginners
      • AI Tips
      • Make Money with AI
    • Reviews
    • Tools
      • Best AI Tools
      • Crypto Market Cap List
      • Stock Market Overview
      • Market Heatmap
    • Contact
    Bytecore News
    Home»Uncategorized»Kelp DAO blames LayerZero defaults for $290m rsETH bridge disaster
    Uncategorized

    Kelp DAO blames LayerZero defaults for $290m rsETH bridge disaster

    April 20, 20264 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email
    coinbase



    Kelp DAO says a LayerZero “default” single‑validator setup helped enable a $290m rsETH bridge hack, forcing a messy blame game and a rushed security migration.

    Summary

    • Kelp DAO disputes LayerZero’s post‑mortem on the $290m rsETH bridge hack, saying a risky 1/1 validator setup was LayerZero’s own default
    • The exploit drained 116,500 rsETH, around $290–$293m and roughly 18% of rsETH’s supply, in what analysts call 2026’s largest DeFi loss so far
    • LayerZero now says it will stop signing messages for any app using a single‑validator DVN and force a migration to multi‑verifier security

    Kelp DAO has pushed back against LayerZero’s official explanation of a $290 million bridge exploit, arguing that the “single‑validator” setup that let an attacker walk off with 116,500 rsETH was not reckless customization but a default configuration in LayerZero’s own guidelines.

    coinbase

    The liquidity re‑staking protocol told CoinDesk the 1‑of‑1 Decentralized Verifier Network (DVN) used on its rsETH cross‑chain route “followed LayerZero’s documented defaults” and that the validator stack compromised by the attacker “is part of LayerZero’s own infrastructure,” rather than an unvetted third party.

    The attack, which hit on April 18, minted or released 116,500 rsETH to an attacker‑controlled address — about 18% of the token’s supply — and translated into losses of roughly $290–$293 million at the time, making it the largest DeFi exploit of 2026 so far.

    In its investigation report and follow‑up statements, LayerZero has insisted that “LayerZero’s protocol was not broken,” arguing instead that Kelp DAO “deployed a single‑point‑of‑failure DVN in production” for a token with more than $1 billion in total value locked.

    The interoperability firm said “operating a single‑point‑of‑failure configuration meant there was no independent verifier to catch and reject a forged message” and claimed it had previously communicated “best practices around DVN diversification” to Kelp DAO and other partners.

    Security researchers and auditors, including SlowMist co‑founder Yu Xian, have confirmed that the rsETH bridge route used a 1/1 DVN — effectively a single signature — rather than a 2/2 or multi‑DVN stack, calling it a “single‑signature single point” vulnerability that may have been aided by social engineering.

    A detailed post‑mortem from DeFi tracking site DeFiPrime notes that LayerZero’s OApp model lets applications choose how many DVNs must sign off on a message, with 2‑of‑3 or 3‑of‑5 configurations commonly recommended for high‑value deployments, but says Kelp’s adapter “was configured to accept the attestation of a single verifier” run by LayerZero Labs.

    That design meant “one forged signature was enough to make any cross‑chain message look real,” allowing the attacker to feed the bridge a fake instruction that mimicked a valid message from another chain and triggered the release of 116,500 rsETH “out of thin air” to their wallet.

    Kelp DAO’s team counters that they implemented LayerZero’s own public code and defaults across multiple networks and that the DVN exploited “was operated by LayerZero itself,” implying that responsibility sits at least partly with the infrastructure provider rather than solely with the application.

    LayerZero has now taken the unusual step of promising it “will stop signing messages for any applications using a single‑validator setup” and is forcing a “security migration” that will require all OApps to move to multi‑DVN architectures if they want to keep using the protocol.

    The fallout goes well beyond one re‑staking token.

    As crypto.news reported in an earlier story on the rsETH exploit and LayerZero’s attribution of the attack to North Korea’s Lazarus Group, the incident has reignited a broader debate over bridge design, default configurations and who ultimately bears responsibility when modular cross‑chain infrastructure goes wrong.

    Related crypto.news stories you can link in copy include coverage of the Kelp DAO–LayerZero exploit and Lazarus attribution, analysis of earlier cross‑chain bridge hacks, and reporting on how re‑staking and liquid‑staking protocols concentrate smart‑contract risk across multiple chains.



    Source link

    notion
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    CryptoExpert
    • Website

    Related Posts

    Dogecoin Could Be Setting Up For High-Beta Rally After Final Shakeout

    May 18, 2026

    Analyst Predicts Bitcoin And Ethereum Price For The Rest Of 2026, What To Expect

    May 18, 2026

    Bitcoin, Altcoins Turn Bearish As Inflation Worries Pressure Markets

    May 18, 2026

    Why most fail, and what actually works

    May 18, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    synthesia
    Latest Posts

    From Zero to Claude Code in 19 Minutes (no code)

    June 19, 2026

    Morgan Stanley Sets 0.14% Fee on Amended Ethereum and Solana ETFs Filing

    June 19, 2026

    Aave avoided collapse, but its $8.45B stress test exposed deeper risks

    June 19, 2026

    CME Group to Sue CFTC Over Approval of Bitcoin Perpetual Futures

    June 19, 2026

    Malta Weighs Legal Framework for DAOs and DeFi Projects

    June 19, 2026
    aistudios
    LEGAL INFORMATION
    • Privacy Policy
    • Terms Of Service
    • Social Media Disclaimer
    • DMCA Compliance
    • Anti-Spam Policy
    Top Insights

    Franklin Templeton new ETFs would convert US companies stock dividends into Bitcoin exposure

    June 19, 2026

    LDO Price Prediction: Whales Are Long but the Tape Keeps Leaking — $0.25 or Bounce?

    June 19, 2026
    livechat
    Facebook X (Twitter) Instagram Pinterest
    © 2026 BytecoreNews.com - All rights reserved.

    Type above and press Enter to search. Press Esc to cancel.