todayonchain.com

KelpDAO hack highlights DeFi’s shift from coding flaws to operational risks

Crypto Briefing
The KelpDAO exploit shows that DeFi threats are moving from smart contract bugs to operational vulnerabilities in off-chain infrastructure like RPC nodes.

Summary

The April 18 KelpDAO exploit, which resulted in the loss of $290 to $293 million in rsETH, marks a significant shift in DeFi security risks. Unlike traditional hacks caused by Solidity coding flaws, this attack targeted off-chain infrastructure, specifically through RPC poisoning and a centralized '1-of-1' verification process. Attributed to the Lazarus Group, the breach highlights that even secure smart contracts are vulnerable if the infrastructure connecting them to external data is compromised. Consequently, investors and developers are urged to prioritize the security of verification pipelines and eliminate single points of failure to mitigate emerging operational risks.

(Source:Crypto Briefing)