|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
暗号通貨のニュース記事
LayerZero が攻撃を受ける: 2 億 9,200 万ドルの Kelp DAO のハッキングにより重大な脆弱性が暴露され、数十億人が危険にさらされる
2026/04/24 18:09
2 億 9,200 万ドルの Kelp DAO ハッキングにより、LayerZero の重大なセキュリティ欠陥が明らかになり、OApp 全体で 45 億ドルが危険にさらされています。この分析では、エクスプロイト、そのシステムへの影響、業界の迅速な対応について詳しく説明し、堅牢なセキュリティが DeFi の将来にとって最も重要であることを強調しています。

LayerZero Under Fire: $292M Kelp DAO Hack Exposes Critical Vulnerability, Billions at Risk
LayerZero が攻撃を受ける: 2 億 9,200 万ドルの Kelp DAO のハッキングにより重大な脆弱性が暴露され、数十億人が危険にさらされる
The $292M Kelp DAO hack spotlights a critical LayerZero security flaw, imperiling nearly half its OApps and $4.5B. A crucial reminder: seamless interoperability needs ironclad security.
2 億 9,200 万ドルの Kelp DAO ハッキングは、LayerZero の重大なセキュリティ欠陥に焦点を当て、OApps のほぼ半分と 45 億ドルを危険にさらします。重要な注意事項: シームレスな相互運用には堅牢なセキュリティが必要です。
The Kelp DAO Debacle: A Single Point of Failure
Kelp DAO の大失敗: 単一障害点
On April 18, 2026, the digital streets saw a staggering $292 million vanish from Kelp DAO. The culprit? A glaring misconfiguration in LayerZero’s Decentralized Verifier Network (DVN) setup, specifically a "1-of-1" arrangement. This single-point-of-failure allowed a compromised verifier to mint 116,500 unbacked rsETH tokens. These phantom tokens then found their way to Aave, where they were used as collateral to borrow $230 million, leaving a trail of bad debt and a very real headache for the lending platform.
2026 年 4 月 18 日、デジタル ストリートでは、Kelp DAO から 2 億 9,200 万ドルという驚くべき金額が消えました。犯人は? LayerZero の分散型検証ネットワーク (DVN) セットアップにおける明らかな構成ミス、特に「1-of-1」構成。この単一障害点により、侵害された検証者が 116,500 個の裏付けのない rsETH トークンを鋳造することができました。これらの幻のトークンはその後 Aave に流れ込み、そこで 2 億 3,000 万ドルを借りるための担保として使用され、不良債権の痕跡が残り、融資プラットフォームにとって非常に深刻な悩みの種となりました。
Investigators have pointed fingers at the infamous Lazarus Group, North Korea's notorious hacking syndicate, suggesting a sophisticated attack that hijacked DVN validation by poisoning RPC nodes. It's a classic caper, but with a modern, digital twist.
捜査当局は、北朝鮮の悪名高いハッキングシンジケートであるLazarus Groupを指摘し、RPCノードをポイズニングすることでDVN検証をハイジャックした高度な攻撃を示唆している。クラシックなケーパーですが、現代的でデジタル的なひねりが加えられています。
Billions on the Brink: The Systemic Risk Unveiled
数十億人が危機に瀕: 明らかになるシステミックリスク
The plot thickens with a Dune Analytics report, revealing a rather sobering truth: 47% of LayerZero-powered omnichain applications (OApps) are operating with this same vulnerable 1-of-1 DVN configuration. The combined exposure? A jaw-dropping $4.5 billion. Leading the charge in this precarious position is Tether’s omnichain stablecoin, USDT0, which alone accounts for $4.065 billion of the identified risk across its Ethereum, Optimism, and Base deployments. While much of USDT0’s activity is secured, a breach in these specific contracts could send tremors through lending markets.
Dune Analytics のレポートによって陰謀はさらに深まり、かなり厳粛な真実が明らかになります。LayerZero を利用したオムニチェーン アプリケーション (OApp) の 47% が、これと同じ脆弱な 1-of-1 DVN 構成で動作しているということです。複合露出?驚愕の45億ドル。この不安定な立場で先頭に立っているのはテザーのオムニチェーン ステーブルコイン USDT0 で、これだけで同社のイーサリアム、オプティミズム、ベース展開全体で特定されたリスクのうち 40 億 6,500 万ドルを占めています。 USDT0 の活動の多くは安全に保たれていますが、これらの特定の契約に違反があれば、融資市場に動揺が生じる可能性があります。
Other digital darlings like Pendle Finance’s PENDLE token and Aethir’s ATH token also share this vulnerability, though their lower collateral acceptance on major platforms might offer a slim silver lining. This isn't just about a single project's oversight; it highlights a systemic risk in DeFi, where the default settings for new deployments can inadvertently create widespread vulnerability.
Pendle Finance の PENDLE トークンや Aethir の ATH トークンなどの他のデジタル人気銘柄もこの脆弱性を共有していますが、主要なプラットフォームでの担保受け入れが低いことがわずかな希望の兆しをもたらす可能性があります。これは単一のプロジェクトの見落としだけではありません。これは、新しい導入のデフォルト設定が意図せず広範囲にわたる脆弱性を生み出す可能性があるという、DeFi におけるシステムリスクを浮き彫りにしています。
LayerZero's Double-Edged Sword: Innovation Meets Imperfection
LayerZero の両刃の剣: 革新と不完全性の融合
It's an interesting duality. On one hand, LayerZero has been celebrated as a cornerstone of interoperability, a vital piece of the "plumbing" for Web3's future, as evidenced by its recent market performance and increasing developer interest. Its promise to integrate multiple blockchains is seen by many as key to a truly global blockchain solution. Yet, the Kelp DAO incident throws a wrench into this narrative, underscoring that groundbreaking innovation, if not coupled with ironclad security, can become a liability.
興味深い二面性ですね。一方で、LayerZero は、最近の市場パフォーマンスと開発者の関心の高まりから明らかなように、相互運用性の基礎、Web3 の将来に向けた「配管」の重要な部分として高く評価されています。複数のブロックチェーンを統合するという同社の約束は、真にグローバルなブロックチェーン ソリューションの鍵であると多くの人がみなしています。しかし、Kelp DAO 事件はこの物語に一石を投じ、画期的なイノベーションが、強固なセキュリティと結びついていない場合には、責任を負う可能性があることを強調しています。
The criticism that the 1-of-1 DVN setup is often the default for new deployments—a point raised by Kelp DAO itself—is particularly poignant. It suggests that while the industry races forward, the onus of implementing secure configurations often falls on individual projects, some of which may be ill-equipped. My two cents? The ambition for a seamlessly connected crypto world must be matched by an equally rigorous commitment to security by design, not as an afterthought. It's not enough to build the roads; we need robust guardrails too.
1-of-1 DVN セットアップが新しい展開のデフォルトになることが多いという批判 (Kelp DAO 自身が提起した点) は、特に心を痛めます。これは、業界が先を急ぐ一方で、安全な構成を実装する責任は個々のプロジェクトに課せられることが多く、その中には設備が整っていないプロジェクトも含まれることを示唆しています。私の2セント?シームレスに接続された暗号世界への野心は、後付けではなく、設計によるセキュリティへの同様の厳格な取り組みと一致する必要があります。道路を建設するだけでは十分ではありません。頑丈なガードレールも必要です。
Patchwork and Progress: The Industry's Swift Response
パッチワークと進歩:業界の迅速な対応
Thankfully, the crypto community isn't one to sit idly by. The Kelp DAO exploit has spurred a commendable flurry of activity. LayerZero quickly deprecated compromised RPC nodes and announced a policy shift to stop signing messages for applications clinging to 1-of-1 configurations. USDT0, too, hit the brakes on its bridging infrastructure, signaling a proactive, if belated, response. Perhaps most encouragingly, fixing these vulnerabilities doesn't demand a full-scale protocol revamp; OApp owners can directly update DVN configurations. Wrapped Bitcoin (wBTC) is already leading the charge, transitioning away from 1-of-1 setups by April 26, 2026.
ありがたいことに、暗号通貨コミュニティは手をこまねいているわけではありません。 Kelp DAO エクスプロイトは、賞賛に値する一連の活動を引き起こしました。 LayerZero は、侵害された RPC ノードをすぐに非推奨にし、1-of-1 構成に固執するアプリケーションのメッセージへの署名を停止するポリシーの変更を発表しました。 USDT0 もブリッジ インフラストラクチャにブレーキを踏み、遅ればせながら積極的な対応を示しました。おそらく最も心強いのは、これらの脆弱性を修正するためにプロトコルを全面的に刷新する必要がないことです。 OApp 所有者は、DVN 構成を直接更新できます。ラップされたビットコイン (wBTC) はすでに先頭に立ち、2026 年 4 月 26 日までに 1-of-1 セットアップから移行します。
Stay Nimble, Stay Secure
機敏さを保ち、安全性を保ちます
For the savvy investor, the message is clear: keep an eagle eye on the security configurations of your digital holdings, especially those deployed on LayerZero. Assets like USDT0, while fundamental, remain under the security microscope until their DVN configurations are fortified. The Kelp DAO hack is a potent reminder that in the wild west of crypto, decentralization without robust security isn't a recipe for freedom, but for potential fiscal fiascos. So, as the market ebbs and flows, let's all endeavor to be a little more secure, a little more vigilant, and a lot less susceptible to the next big hack. After all, a secure blockchain is a happy blockchain, right?
賢明な投資家にとって、メッセージは明確です。デジタル資産、特に LayerZero に展開されている資産のセキュリティ構成を注意深く監視してください。 USDT0 のような資産は、基本的なものではありますが、DVN 構成が強化されるまでセキュリティ監視下に置かれます。 Kelp DAO ハッキングは、暗号通貨の荒野において、堅牢なセキュリティのない分散化は自由を手に入れるレシピではなく、潜在的な財政的大失敗を招くことを強く思い出させます。したがって、市場の盛衰に合わせて、もう少し安全に、もう少し警戒して、次の大きなハッキングの影響をあまり受けないよう全員で努力しましょう。結局のところ、安全なブロックチェーンは幸せなブロックチェーンですよね?
免責事項:info@kdj.com
提供される情報は取引に関するアドバイスではありません。 kdj.com は、この記事で提供される情報に基づいて行われた投資に対して一切の責任を負いません。暗号通貨は変動性が高いため、十分な調査を行った上で慎重に投資することを強くお勧めします。
このウェブサイトで使用されているコンテンツが著作権を侵害していると思われる場合は、直ちに当社 (info@kdj.com) までご連絡ください。速やかに削除させていただきます。

































