• bitcoinBitcoin (BTC) $ 79,097.00
  • ethereumEthereum (ETH) $ 2,400.16
  • tetherTether (USDT) $ 1.00
  • xrpXRP (XRP) $ 1.45
  • bnbBNB (BNB) $ 649.24
  • usd-coinUSDC (USDC) $ 0.999767
  • solanaSolana (SOL) $ 88.24
  • tronTRON (TRX) $ 0.329160
  • staked-etherLido Staked Ether (STETH) $ 2,265.05
  • figure-helocFigure Heloc (FIGR_HELOC) $ 1.03
  • dogecoinDogecoin (DOGE) $ 0.097790
  • whitebitWhiteBIT Coin (WBT) $ 56.39
  • usdsUSDS (USDS) $ 0.999638
  • hyperliquidHyperliquid (HYPE) $ 40.94
  • cardanoCardano (ADA) $ 0.255137
  • wrapped-stethWrapped stETH (WSTETH) $ 2,779.67
  • leo-tokenLEO Token (LEO) $ 10.20
  • bitcoin-cashBitcoin Cash (BCH) $ 464.66
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 76,243.00
  • moneroMonero (XMR) $ 375.42
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.998762
  • chainlinkChainlink (LINK) $ 9.49
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 2,466.93
  • stellarStellar (XLM) $ 0.181046
  • canton-networkCanton (CC) $ 0.153620
  • memecoreMemeCore (M) $ 4.28
  • wrapped-eethWrapped eETH (WEETH) $ 2,465.31
  • zcashZcash (ZEC) $ 322.30
  • ethena-usdeEthena USDe (USDE) $ 0.999155
  • susdssUSDS (SUSDS) $ 1.08
  • daiDai (DAI) $ 0.999684
  • litecoinLitecoin (LTC) $ 56.40
  • usd1-wlfiUSD1 (USD1) $ 0.999924
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 76,366.00
  • avalanche-2Avalanche (AVAX) $ 9.57
  • hedera-hashgraphHedera (HBAR) $ 0.091936
  • suiSui (SUI) $ 0.971605
  • wethWETH (WETH) $ 2,268.37
  • rainRain (RAIN) $ 0.007792
  • shiba-inuShiba Inu (SHIB) $ 0.000006
  • paypal-usdPayPal USD (PYUSD) $ 0.999891
  • usdt0USDT0 (USDT0) $ 0.998824
  • the-open-networkToncoin (TON) $ 1.37
  • crypto-com-chainCronos (CRO) $ 0.070876
  • hashnote-usycCircle USYC (USYC) $ 1.12
  • tether-goldTether Gold (XAUT) $ 4,718.89
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.079574
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • bittensorBittensor (TAO) $ 245.56
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.22
  • global-dollarGlobal Dollar (USDG) $ 0.999871
  • pax-goldPAX Gold (PAXG) $ 4,720.46
  • polkadotPolkadot (DOT) $ 1.30
  • uniswapUniswap (UNI) $ 3.42
  • mantleMantle (MNT) $ 0.640145
  • skySky (SKY) $ 0.084367
  • nearNEAR Protocol (NEAR) $ 1.43
  • falcon-financeFalcon USD (USDF) $ 0.997809
  • okbOKB (OKB) $ 84.73
  • pi-networkPi Network (PI) $ 0.169543
  • little-pepe-5Little Pepe (LILPEPE) $ 2.16
  • aster-2Aster (ASTER) $ 0.686222
  • htx-daoHTX DAO (HTX) $ 0.000002
  • syrupusdcsyrupUSDC (SYRUPUSDC) $ 1.15
  • pepePepe (PEPE) $ 0.000004
  • janus-henderson-anemoy-treasury-fundJanus Henderson Anemoy Treasury Fund (JTRSY) $ 1.10
  • ripple-usdRipple USD (RLUSD) $ 1.00
  • aaveAave (AAVE) $ 94.15
  • internet-computerInternet Computer (ICP) $ 2.55
  • bitget-tokenBitget Token (BGB) $ 1.95
  • usddUSDD (USDD) $ 1.00
  • ethereum-classicEthereum Classic (ETC) $ 8.67
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.13
  • bfusdBFUSD (BFUSD) $ 0.999900
  • ondo-financeOndo (ONDO) $ 0.268411
  • kucoin-sharesKuCoin (KCS) $ 8.60
  • pump-funPump.fun (PUMP) $ 0.001920
  • gatechain-tokenGate (GT) $ 7.43
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 4.00
  • quant-networkQuant (QNT) $ 74.84
  • morphoMorpho (MORPHO) $ 1.94
  • united-stablesUnited Stables (U) $ 0.999736
  • eutblSpiko EU T-Bills Money Market Fund (EUTBL) $ 1.23
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.094412
  • jito-staked-solJito Staked SOL (JITOSOL) $ 124.46
  • ethenaEthena (ENA) $ 0.111654
  • kaspaKaspa (KAS) $ 0.035089
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 2,404.69
  • render-tokenRender (RENDER) $ 1.85
  • cosmosCosmos Hub (ATOM) $ 1.88
  • binance-peg-wethBinance-Peg WETH (WETH) $ 2,262.26
  • algorandAlgorand (ALGO) $ 0.104999
  • rocket-pool-ethRocket Pool ETH (RETH) $ 2,631.35
  • nexoNEXO (NEXO) $ 0.917372
  • worldcoin-wldWorldcoin (WLD) $ 0.269564
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 0.999945
  • usdtbUSDtb (USDTB) $ 0.999638
  • superstate-short-duration-us-government-securities-fund-ustbSuperstate Short Duration U.S. Government Securities Fund (USTB) (USTB) $ 11.06
  • wbnbWrapped BNB (WBNB) $ 759.61
  • aptosAptos (APT) $ 0.978967
  • ignition-fbtcFunction FBTC (FBTC) $ 76,389.00
  • arbitrumArbitrum (ARB) $ 0.127961
  • blockchain-capitalBlockchain Capital (BCAP) $ 82.76
  • filecoinFilecoin (FIL) $ 0.956536
  • flare-networksFlare (FLR) $ 0.008098
  • official-trumpOfficial Trump (TRUMP) $ 2.99
  • syrupusdtsyrupUSDT (SYRUPUSDT) $ 1.11
  • justJUST (JST) $ 0.081054
  • jupiter-exchange-solanaJupiter (JUP) $ 0.177640
  • vechainVeChain (VET) $ 0.007275
  • binance-staked-solBinance Staked SOL (BNSOL) $ 108.24
  • beldexBeldex (BDX) $ 0.079845
  • midnight-3Midnight (NIGHT) $ 0.037053
  • xdce-crowd-saleXDC Network (XDC) $ 0.030783
  • ousgOUSG (OUSG) $ 115.00
  • hash-2Provenance Blockchain (HASH) $ 0.010426
  • yldsYLDS (YLDS) $ 0.999852
  • new-x-ceo-is-backNEW X CEO IS BACK (XFLOKI) $ 0.506041
  • bridged-usdc-polygon-pos-bridgePolygon Bridged USDC (Polygon PoS) (USDC.E) $ 0.999720
  • ghoGHO (GHO) $ 0.998915
  • solv-btcSolv Protocol BTC (SOLVBTC) $ 76,461.00
  • stable-2​​Stable (STABLE) $ 0.025957
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 76,491.00
  • bonkBonk (BONK) $ 0.000006
  • dexeDeXe (DEXE) $ 12.03
  • usual-usdUsual USD (USD0) $ 0.997878
  • clbtcclBTC (CLBTC) $ 76,920.00
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.008584
  • edgexedgeX (EDGE) $ 1.48
  • pancakeswap-tokenPancakeSwap (CAKE) $ 1.55
  • true-usdTrueUSD (TUSD) $ 0.998011
  • a7a5A7A5 (A7A5) $ 0.012487
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.215178
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 2,419.84
  • chilizChiliz (CHZ) $ 0.046359
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 0.712308
  • kinetic-staked-hypeKinetiq Staked HYPE (KHYPE) $ 33.97
  • dashDash (DASH) $ 36.57
  • tbtctBTC (TBTC) $ 70,942.00
  • siren-2Siren (SIREN) $ 0.635998
  • wrappedm-by-m0WrappedM by M0 (WM) $ 1.00
  • adi-tokenADI (ADI) $ 4.30
  • euro-coinEURC (EURC) $ 1.17
  • blockstackStacks (STX) $ 0.231350
  • sei-networkSei (SEI) $ 0.061946
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.998509
  • monadMonad (MON) $ 0.034961
  • c8ntinuumc8ntinuum (CTM) $ 0.087592
  • tezosTezos (XTZ) $ 0.379532
  • mantle-staked-etherMantle Staked Ether (METH) $ 2,455.82
  • venice-tokenVenice Token (VVV) $ 8.91
  • layerzeroLayerZero (ZRO) $ 1.60
  • polygon-pos-bridged-dai-polygon-posPolygon PoS Bridged DAI (Polygon POS) (DAI) $ 0.999983
  • janus-henderson-anemoy-aaa-clo-fundJanus Henderson Anemoy AAA CLO Fund (JAAA) $ 1.03
  • bianrensheng币安人生 (BinanceLife) (币安人生) $ 0.401849
  • resolv-wstusrResolv wstUSR (WSTUSR) $ 1.13
  • cocaCOCA (COCA) $ 1.30
  • ether-fiEther.fi (ETHFI) $ 0.470802
  • aerodrome-financeAerodrome Finance (AERO) $ 0.422780
  • usxUSX (USX) $ 0.999690
  • doge-strategyDoge Strategy (DOGESTR) $ 0.288297
  • liquid-staked-ethereumLiquid Staked ETH (LSETH) $ 2,406.26
  • kinesis-goldKinesis Gold (KAU) $ 153.31
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 76,200.00
  • sun-tokenSun Token (SUN) $ 0.018769
  • spx6900SPX6900 (SPX) $ 0.384649
  • decredDecred (DCR) $ 20.59
  • curve-dao-tokenCurve DAO (CRV) $ 0.235898
  • wrapped-flareWrapped Flare (WFLR) $ 0.009961
  • celestiaCelestia (TIA) $ 0.385746
  • hastra-primePRIME (PRIME) $ 1.03
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 2,266.86
  • injective-protocolInjective (INJ) $ 3.37
  • steakhouse-usdc-morpho-vaultSteakhouse USDC Morpho Vault (STEAKUSDC) $ 1.12
  • lido-daoLido DAO (LDO) $ 0.391454
  • apenftAINFT (NFT) $ 0.00000033
  • crvusdcrvUSD (CRVUSD) $ 0.999933
  • bitcoin-svBitcoin SV (BSV) $ 16.36
  • gnosisGnosis (GNO) $ 123.85
  • binance-peg-xrpBinance-Peg XRP (XRP) $ 1.59
  • flokiFLOKI (FLOKI) $ 0.000034
  • ether-fi-liquid-ethEther.Fi Liquid ETH (LIQUIDETH) $ 2,443.47
  • bittorrentBitTorrent (BTT) $ 0.00000033
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 2,421.84
  • conflux-tokenConflux (CFX) $ 0.060759
  • doublezeroDoubleZero (2Z) $ 0.086005
  • noonNoon (NOON) $ 0.751949
  • sbtc-2sBTC (SBTC) $ 77,039.00
  • kinesis-silverKinesis Silver (KAG) $ 77.81
  • kaiaKaia (KAIA) $ 0.048697
  • jasmycoinJasmyCoin (JASMY) $ 0.005742
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 115.56
  • usdaiUSDai (USDAI) $ 0.999363
  • savings-usddSavings USDD (SUSDD) $ 1.03
  • ravedaoRaveDAO (RAVE) $ 1.12
  • pyth-networkPyth Network (PYTH) $ 0.048491
  • syrupMaple Finance (SYRUP) $ 0.237029
  • msolMarinade Staked SOL (MSOL) $ 133.18
  • fraxLegacy Frax Dollar (FRAX) $ 0.992999
  • arbitrum-bridged-weth-arbitrum-oneArbitrum Bridged WETH (Arbitrum One) (WETH) $ 2,265.06

Kelp DAO claims LayerZero’s ‘default’ settings are what actually caused the massive $290 million disaster

0 0


The popular Spiderman meme showing three identical superheroes pointing fingers at each other is having its crypto moment today.

Kelp DAO is set to push back on LayerZero’s post-mortem of Sunday’s $290 million exploit, which essentially blames Kelp, a L2 source familiar with the matter told CoinDesk. Kelp plans to dispute the cross-chain messaging firm’s claim that it ignored repeated warnings to move away from a single-verifier setup. CoinDesk has reviewed and verified the memo Kelp plans to publish.

Kelp is a liquid restaking protocol that takes user-deposited ether, routes it through a yield-generating system called EigenLayer, and issues a receipt token, rsETH, in exchange.

LayerZero is the cross-chain messaging infrastructure that moves rsETH between blockchains, using entities called DVNs (decentralized verifier networks) to verify whether a cross-chain transfer is valid.

On Saturday, attackers drained 116,500 rsETH, worth about $290 million, from Kelp’s LayerZero-powered bridge by poisoning the servers that LayerZero’s verifier relied on to check transactions.

Kelp, the source said, is planning on saying the DVN that was compromised via what it calls a “sophisticated state-sponsored attack” was LayerZero’s own infrastructure, not a third-party verifier.

Attackers compromised two of LayerZero’s own servers that check whether cross-chain transactions are legitimate, then flooded the backup servers with junk traffic to force LayerZero’s verifier onto the compromised ones.

All of that infrastructure was built and run by LayerZero, not Kelp, the sourceclaimed.

The source contested LayerZero’s framing of the “1/1 configuration” as a fringe choice made against guidance. LayerZero’s post-mortem said KelpDAO chose a 1-of-1 DVN setup despite expressing recommendations to configure multi-DVN redundancy.

A “1/1 configuration” means only a single validator must sign off on a cross-chain message for the bridge to act on it, leaving the system with no second check to catch a compromised or forged instruction. A multi-validator configuration (such as 2/3, 3/5, etc.) ensures there is no single point of failure that can approve a forged message on its own.

They added that, through a direct communications channel with LayerZero, which has been open since July 2024, they produced no specific recommendation for Kelp to change the rsETH DVN configuration.

LayerZero’s own quickstart guide and default GitHub configuration point to a 1/1 DVN setup, the source told CoinDesk, adding 40% of protocols on LayerZero are currently using the same configuration.

The configuration Kelp ran also appears in LayerZero’s own V2 OApp Quickstart, where the sample layerzero.config.ts wires every pathway with one required DVN and no optional DVNs. That’s the same 1/1 structure.

Kelp’s core restaking contracts were not touched, and the exploit was isolated to the bridge layer, they added. Its emergency pause, 46 minutes after the drain, blocked two follow-up attempts that would have released an additional ~$200 million in rsETH.

CoinDesk reached out to LayerZero for comment on the story and didn’t hear back by the time of publication.

‘Deflecting responsibility’

Security researchers are also not buying LayerZero’s isolated framing, which pinned the blame on Kelp.

Kelp is a liquid restaking protocol. Its core competency is staking infrastructure, EigenLayer integration, and liquid staking token management. When integrating with LayerZero, Kelp relied on LayerZero’s documentation, their defaults, and their team’s guidance to make configuration decisions, the source claimed.

Yearn Finance core team developer Artem K, who is popularly known as @banteg on X, posted a technical review of LayerZero’s public deployment code and said that the reference setup ships with single-source verification defaults across every major chain, including Ethereum, BSC, Polygon, Arbitrum and Optimism.

That deployment also leaves a public endpoint exposed that leaks the list of configured servers to anyone who queries it.

Banteg flagged in his analysis that he can’t prove which configuration Kelp used, but noted that LayerZero usually asks new operators to use its default setup, which its post-mortem criticized.

Chainlink community manager Zach Rynes put it bluntly on X, alleging that LayerZero was “deflecting responsibility” for its own compromised infrastructure and accused the company of throwing Kelp under the bus for trusting a setup LayerZero itself supported.

As such, LayerZero has said it will no longer sign messages for any application running a single-verifier setup, forcing a protocol-wide migration.

Read more: ‘DeFi is dead’: crypto community scrambles after this year’s biggest hack exposes contagion risk



Source link

Leave A Reply

Your email address will not be published.