• bitcoinBitcoin (BTC) $ 77,861.00
  • ethereumEthereum (ETH) $ 2,313.97
  • tetherTether (USDT) $ 1.00
  • xrpXRP (XRP) $ 1.43
  • bnbBNB (BNB) $ 636.42
  • usd-coinUSDC (USDC) $ 0.999822
  • solanaSolana (SOL) $ 85.54
  • tronTRON (TRX) $ 0.329103
  • staked-etherLido Staked Ether (STETH) $ 2,265.05
  • figure-helocFigure Heloc (FIGR_HELOC) $ 1.04
  • dogecoinDogecoin (DOGE) $ 0.096287
  • whitebitWhiteBIT Coin (WBT) $ 55.06
  • usdsUSDS (USDS) $ 0.999472
  • hyperliquidHyperliquid (HYPE) $ 41.05
  • leo-tokenLEO Token (LEO) $ 10.28
  • wrapped-stethWrapped stETH (WSTETH) $ 2,779.67
  • bitcoin-cashBitcoin Cash (BCH) $ 457.22
  • cardanoCardano (ADA) $ 0.246767
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 76,243.00
  • moneroMonero (XMR) $ 372.23
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.998762
  • chainlinkChainlink (LINK) $ 9.27
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 2,466.93
  • stellarStellar (XLM) $ 0.176077
  • canton-networkCanton (CC) $ 0.150134
  • zcashZcash (ZEC) $ 334.32
  • wrapped-eethWrapped eETH (WEETH) $ 2,465.31
  • memecoreMemeCore (M) $ 4.26
  • daiDai (DAI) $ 0.999685
  • susdssUSDS (SUSDS) $ 1.08
  • usd1-wlfiUSD1 (USD1) $ 1.00
  • litecoinLitecoin (LTC) $ 55.48
  • avalanche-2Avalanche (AVAX) $ 9.30
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 76,366.00
  • ethena-usdeEthena USDe (USDE) $ 0.999295
  • hedera-hashgraphHedera (HBAR) $ 0.090350
  • suiSui (SUI) $ 0.935616
  • wethWETH (WETH) $ 2,268.37
  • shiba-inuShiba Inu (SHIB) $ 0.000006
  • rainRain (RAIN) $ 0.007470
  • paypal-usdPayPal USD (PYUSD) $ 0.999741
  • usdt0USDT0 (USDT0) $ 0.998824
  • the-open-networkToncoin (TON) $ 1.36
  • crypto-com-chainCronos (CRO) $ 0.069736
  • hashnote-usycCircle USYC (USYC) $ 1.12
  • tether-goldTether Gold (XAUT) $ 4,689.01
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.077127
  • global-dollarGlobal Dollar (USDG) $ 0.999880
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.22
  • bittensorBittensor (TAO) $ 243.54
  • pax-goldPAX Gold (PAXG) $ 4,691.30
  • mantleMantle (MNT) $ 0.638899
  • uniswapUniswap (UNI) $ 3.26
  • polkadotPolkadot (DOT) $ 1.22
  • skySky (SKY) $ 0.084935
  • nearNEAR Protocol (NEAR) $ 1.39
  • falcon-financeFalcon USD (USDF) $ 0.996921
  • okbOKB (OKB) $ 83.67
  • pi-networkPi Network (PI) $ 0.167161
  • little-pepe-5Little Pepe (LILPEPE) $ 2.16
  • htx-daoHTX DAO (HTX) $ 0.000002
  • aster-2Aster (ASTER) $ 0.671507
  • syrupusdcsyrupUSDC (SYRUPUSDC) $ 1.15
  • pepePepe (PEPE) $ 0.000004
  • janus-henderson-anemoy-treasury-fundJanus Henderson Anemoy Treasury Fund (JTRSY) $ 1.10
  • ripple-usdRipple USD (RLUSD) $ 0.999952
  • aaveAave (AAVE) $ 92.28
  • usddUSDD (USDD) $ 1.00
  • bitget-tokenBitget Token (BGB) $ 1.94
  • internet-computerInternet Computer (ICP) $ 2.46
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.13
  • ethereum-classicEthereum Classic (ETC) $ 8.45
  • bfusdBFUSD (BFUSD) $ 1.00
  • ondo-financeOndo (ONDO) $ 0.258821
  • gatechain-tokenGate (GT) $ 7.35
  • kucoin-sharesKuCoin (KCS) $ 8.39
  • morphoMorpho (MORPHO) $ 1.90
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 4.00
  • quant-networkQuant (QNT) $ 72.76
  • pump-funPump.fun (PUMP) $ 0.001785
  • united-stablesUnited Stables (U) $ 1.00
  • eutblSpiko EU T-Bills Money Market Fund (EUTBL) $ 1.23
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.094076
  • jito-staked-solJito Staked SOL (JITOSOL) $ 124.46
  • ethenaEthena (ENA) $ 0.109799
  • cosmosCosmos Hub (ATOM) $ 1.87
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 2,404.69
  • kaspaKaspa (KAS) $ 0.033909
  • render-tokenRender (RENDER) $ 1.79
  • binance-peg-wethBinance-Peg WETH (WETH) $ 2,262.26
  • algorandAlgorand (ALGO) $ 0.103023
  • rocket-pool-ethRocket Pool ETH (RETH) $ 2,631.35
  • nexoNEXO (NEXO) $ 0.898309
  • worldcoin-wldWorldcoin (WLD) $ 0.259653
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 0.999945
  • superstate-short-duration-us-government-securities-fund-ustbSuperstate Short Duration U.S. Government Securities Fund (USTB) (USTB) $ 11.06
  • arbitrumArbitrum (ARB) $ 0.126523
  • wbnbWrapped BNB (WBNB) $ 759.61
  • blockchain-capitalBlockchain Capital (BCAP) $ 82.76
  • ignition-fbtcFunction FBTC (FBTC) $ 76,389.00
  • aptosAptos (APT) $ 0.932960
  • filecoinFilecoin (FIL) $ 0.919510
  • justJUST (JST) $ 0.082848
  • flare-networksFlare (FLR) $ 0.007932
  • official-trumpOfficial Trump (TRUMP) $ 2.84
  • syrupusdtsyrupUSDT (SYRUPUSDT) $ 1.11
  • stable-2​​Stable (STABLE) $ 0.029764
  • beldexBeldex (BDX) $ 0.080105
  • vechainVeChain (VET) $ 0.007216
  • binance-staked-solBinance Staked SOL (BNSOL) $ 108.24
  • midnight-3Midnight (NIGHT) $ 0.036383
  • jupiter-exchange-solanaJupiter (JUP) $ 0.170034
  • ousgOUSG (OUSG) $ 115.01
  • hash-2Provenance Blockchain (HASH) $ 0.010338
  • xdce-crowd-saleXDC Network (XDC) $ 0.029656
  • dexeDeXe (DEXE) $ 12.57
  • new-x-ceo-is-backNEW X CEO IS BACK (XFLOKI) $ 0.506041
  • bridged-usdc-polygon-pos-bridgePolygon Bridged USDC (Polygon PoS) (USDC.E) $ 0.999720
  • ghoGHO (GHO) $ 0.998843
  • solv-btcSolv Protocol BTC (SOLVBTC) $ 76,461.00
  • usdtbUSDtb (USDTB) $ 0.999549
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 76,491.00
  • usual-usdUsual USD (USD0) $ 0.998075
  • bonkBonk (BONK) $ 0.000006
  • yldsYLDS (YLDS) $ 0.999798
  • clbtcclBTC (CLBTC) $ 76,920.00
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.008414
  • true-usdTrueUSD (TUSD) $ 0.998518
  • pancakeswap-tokenPancakeSwap (CAKE) $ 1.50
  • chilizChiliz (CHZ) $ 0.047276
  • a7a5A7A5 (A7A5) $ 0.012416
  • edgexedgeX (EDGE) $ 1.37
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 2,419.84
  • siren-2Siren (SIREN) $ 0.659234
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.209159
  • kinetic-staked-hypeKinetiq Staked HYPE (KHYPE) $ 33.97
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 0.683369
  • tbtctBTC (TBTC) $ 70,942.00
  • dashDash (DASH) $ 35.45
  • wrappedm-by-m0WrappedM by M0 (WM) $ 1.00
  • adi-tokenADI (ADI) $ 4.19
  • euro-coinEURC (EURC) $ 1.17
  • blockstackStacks (STX) $ 0.225946
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.999274
  • aerodrome-financeAerodrome Finance (AERO) $ 0.446875
  • sei-networkSei (SEI) $ 0.060927
  • c8ntinuumc8ntinuum (CTM) $ 0.087592
  • janus-henderson-anemoy-aaa-clo-fundJanus Henderson Anemoy AAA CLO Fund (JAAA) $ 1.03
  • mantle-staked-etherMantle Staked Ether (METH) $ 2,455.82
  • layerzeroLayerZero (ZRO) $ 1.59
  • tezosTezos (XTZ) $ 0.363772
  • polygon-pos-bridged-dai-polygon-posPolygon PoS Bridged DAI (Polygon POS) (DAI) $ 0.999983
  • venice-tokenVenice Token (VVV) $ 8.47
  • resolv-wstusrResolv wstUSR (WSTUSR) $ 1.13
  • monadMonad (MON) $ 0.032417
  • cocaCOCA (COCA) $ 1.30
  • usxUSX (USX) $ 0.999666
  • ether-fiEther.fi (ETHFI) $ 0.451106
  • kinesis-goldKinesis Gold (KAU) $ 153.67
  • doge-strategyDoge Strategy (DOGESTR) $ 0.288297
  • liquid-staked-ethereumLiquid Staked ETH (LSETH) $ 2,406.26
  • sun-tokenSun Token (SUN) $ 0.018890
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 76,200.00
  • spx6900SPX6900 (SPX) $ 0.385440
  • bianrensheng币安人生 (BinanceLife) (币安人生) $ 0.355198
  • decredDecred (DCR) $ 19.78
  • hastra-primePRIME (PRIME) $ 1.03
  • wrapped-flareWrapped Flare (WFLR) $ 0.009961
  • crvusdcrvUSD (CRVUSD) $ 0.999439
  • curve-dao-tokenCurve DAO (CRV) $ 0.220481
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 2,266.86
  • injective-protocolInjective (INJ) $ 3.31
  • steakhouse-usdc-morpho-vaultSteakhouse USDC Morpho Vault (STEAKUSDC) $ 1.12
  • celestiaCelestia (TIA) $ 0.358797
  • flokiFLOKI (FLOKI) $ 0.000034
  • lido-daoLido DAO (LDO) $ 0.379314
  • bittorrentBitTorrent (BTT) $ 0.00000032
  • gnosisGnosis (GNO) $ 120.90
  • binance-peg-xrpBinance-Peg XRP (XRP) $ 1.59
  • apenftAINFT (NFT) $ 0.00000032
  • ether-fi-liquid-ethEther.Fi Liquid ETH (LIQUIDETH) $ 2,443.47
  • bitcoin-svBitcoin SV (BSV) $ 15.59
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 2,421.84
  • conflux-tokenConflux (CFX) $ 0.059567
  • zebec-networkZebec Network (ZBCN) $ 0.003107
  • noonNoon (NOON) $ 0.751949
  • sbtc-2sBTC (SBTC) $ 77,039.00
  • doublezeroDoubleZero (2Z) $ 0.082971
  • kinesis-silverKinesis Silver (KAG) $ 75.79
  • kaiaKaia (KAIA) $ 0.048287
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 115.56
  • usdaiUSDai (USDAI) $ 0.999298
  • savings-usddSavings USDD (SUSDD) $ 1.03
  • pyth-networkPyth Network (PYTH) $ 0.049029
  • kite-2Kite (KITE) $ 0.155624
  • jasmycoinJasmyCoin (JASMY) $ 0.005590
  • msolMarinade Staked SOL (MSOL) $ 133.18
  • fraxLegacy Frax Dollar (FRAX) $ 0.993382
  • arbitrum-bridged-weth-arbitrum-oneArbitrum Bridged WETH (Arbitrum One) (WETH) $ 2,265.06

LayerZero blames Kelp’s setup for $290 million exploit, attributes it to North Korea’s Lazarus

0 0


LayerZero has placed responsibility for the $290 million Kelp DAO exploit on Kelp’s own security configuration, saying the liquid restaking protocol ran a single-verifier setup that LayerZero had previously warned against.

The attack used a novel vector targeting the infrastructure layer rather than any protocol code.

Attackers, whom LayerZero attributed with preliminary confidence to North Korea’s Lazarus Group and its TraderTraitor subunit, compromised two of the remote procedure call (RPC) nodes that LayerZero’s verifier relied on to confirm cross-chain transactions.

RPC nodes are the servers that let software read and write data on a blockchain, and LayerZero’s verifier used a mix of internal and external ones for redundancy.

The attackers swapped the binary software running on two of those nodes with malicious versions designed to tell LayerZero’s verifier that a fraudulent transaction had occurred, while continuing to report accurate data to every other system querying those same nodes.

That selective lying was engineered to keep the attack invisible to LayerZero’s own monitoring infrastructure, which queries the same RPCs from different IP addresses.

Compromising two nodes was not enough. LayerZero’s verifier also queried uncompromised external RPC nodes, so the attackers ran a distributed denial-of-service attack on those to force failover to the poisoned ones.

Traffic logs LayerZero shared show the DDoS running between 10:20 a.m. and 11:40 a.m. Pacific Time on Saturday. Once the failover triggered, the compromised nodes told the verifier a valid cross-chain message had arrived, and Kelp’s bridge released 116,500 rsETH to the attackers. The malicious node software then self-destructed, wiping binaries and local logs.

The attack only worked because Kelp ran a 1-of-1 verifier configuration, meaning LayerZero Labs was the sole entity verifying messages to and from the rsETH bridge.

LayerZero’s public integration checklist and direct communications to Kelp had recommended a multi-verifier setup with redundancy, where consensus across several independent verifiers would be required to confirm a message. Under that configuration, poisoning one verifier’s data feed would not have been enough to forge a valid message.

“KelpDAO chose to utilize a 1/1 DVN configuration,” LayerZero wrote, using the protocol’s term for decentralized verifier networks. “A properly hardened configuration would have required consensus across multiple independent DVNs, rendering this attack ineffective even in the event of any single DVN being compromised.”

LayerZero said it has confirmed zero contagion to any other application on the protocol. Every OFT-standard token and application running multi-verifier setups was unaffected.

The LayerZero Labs verifier is back online, and the company said it will no longer sign messages for any application running a 1-of-1 configuration, forcing a protocol-wide migration off single-verifier setups.

The architectural distinction matters for how DeFi prices LayerZero risk going forward.

A protocol-level bug would have implied every OFT token on every chain was potentially at risk. However, a configuration failure by a single integrator, combined with a targeted infrastructure attack, implies the protocol worked as designed and that Kelp’s security choices, not LayerZero’s code, created the opening.

Kelp has not yet publicly responded to LayerZero’s framing or addressed why it operated a 1-of-1 verifier setup despite the explicit recommendations against it.

Lazarus Group has been linked to the Drift Protocol exploit on April 1 and now Kelp on April 18, meaning the same North Korean unit has drained more than $575 million from DeFi in 18 days through two structurally different attack vectors: social engineering governance signers at Drift and poisoning infrastructure RPCs at Kelp.

The group is adapting its playbook faster than DeFi protocols are hardening their defenses.



Source link

Leave A Reply

Your email address will not be published.