|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
价值 2.92 亿美元的 Kelp DAO 黑客攻击揭示了一个关键的 LayerZero 安全漏洞,使 OApp 中的 4.5B 美元面临风险。该分析详细介绍了该漏洞、其系统影响以及行业的快速反应,强调强大的安全性对于 DeFi 的未来至关重要。

LayerZero Under Fire: $292M Kelp DAO Hack Exposes Critical Vulnerability, Billions at Risk
LayerZero 遭受攻击:价值 2.92 亿美元的 Kelp DAO 黑客攻击暴露了严重漏洞,数十亿美元面临风险
The $292M Kelp DAO hack spotlights a critical LayerZero security flaw, imperiling nearly half its OApps and $4.5B. A crucial reminder: seamless interoperability needs ironclad security.
价值 2.92 亿美元的 Kelp DAO 黑客事件凸显了 LayerZero 的一个关键安全漏洞,危及其近一半的 OApp 和 4.5B 美元。重要提醒:无缝互操作性需要铁定的安全性。
The Kelp DAO Debacle: A Single Point of Failure
Kelp DAO 崩溃:单点故障
On April 18, 2026, the digital streets saw a staggering $292 million vanish from Kelp DAO. The culprit? A glaring misconfiguration in LayerZero’s Decentralized Verifier Network (DVN) setup, specifically a "1-of-1" arrangement. This single-point-of-failure allowed a compromised verifier to mint 116,500 unbacked rsETH tokens. These phantom tokens then found their way to Aave, where they were used as collateral to borrow $230 million, leaving a trail of bad debt and a very real headache for the lending platform.
2026 年 4 月 18 日,数字街道上的 Kelp DAO 损失了惊人的 2.92 亿美元。罪魁祸首? LayerZero 的去中心化验证网络 (DVN) 设置中存在明显的错误配置,特别是“1-of-1”安排。这种单点故障允许受感染的验证者铸造 116,500 个无支持的 rsETH 代币。这些虚拟代币随后流向 Aave,在那里它们被用作抵押品借入 2.3 亿美元,留下了一系列坏账,让借贷平台非常头疼。
Investigators have pointed fingers at the infamous Lazarus Group, North Korea's notorious hacking syndicate, suggesting a sophisticated attack that hijacked DVN validation by poisoning RPC nodes. It's a classic caper, but with a modern, digital twist.
调查人员将矛头指向臭名昭著的 Lazarus Group(朝鲜臭名昭著的黑客集团),暗示这是一场复杂的攻击,通过毒害 RPC 节点来劫持 DVN 验证。这是一部经典的喜剧,但带有现代的数字元素。
Billions on the Brink: The Systemic Risk Unveiled
数十亿人濒临崩溃:系统性风险揭晓
The plot thickens with a Dune Analytics report, revealing a rather sobering truth: 47% of LayerZero-powered omnichain applications (OApps) are operating with this same vulnerable 1-of-1 DVN configuration. The combined exposure? A jaw-dropping $4.5 billion. Leading the charge in this precarious position is Tether’s omnichain stablecoin, USDT0, which alone accounts for $4.065 billion of the identified risk across its Ethereum, Optimism, and Base deployments. While much of USDT0’s activity is secured, a breach in these specific contracts could send tremors through lending markets.
Dune Analytics 报告使情节变得更加复杂,揭示了一个相当发人深省的事实:47% 的 LayerZero 支持的全链应用程序 (OApp) 正在使用同样易受攻击的 1-of-1 DVN 配置运行。合并曝光?令人瞠目结舌的 45 亿美元。在这种不稳定的情况下,Tether 的全链稳定币 USDT0 处于领先地位,仅在其以太坊、Optimism 和 Base 部署的已识别风险中,USDT0 就占了 40.65 亿美元。虽然 USDT0 的大部分活动都是受到保护的,但这些特定合约的违反可能会引起借贷市场的震动。
Other digital darlings like Pendle Finance’s PENDLE token and Aethir’s ATH token also share this vulnerability, though their lower collateral acceptance on major platforms might offer a slim silver lining. This isn't just about a single project's oversight; it highlights a systemic risk in DeFi, where the default settings for new deployments can inadvertently create widespread vulnerability.
其他数字宠儿,如 Pendle Finance 的 PENDLE 代币和 Aethir 的 ATH 代币也存在这个漏洞,尽管它们在主要平台上较低的抵押品接受度可能会带来一线希望。这不仅仅是对单个项目的监督;它凸显了 DeFi 中的系统性风险,新部署的默认设置可能会无意中造成广泛的漏洞。
LayerZero's Double-Edged Sword: Innovation Meets Imperfection
LayerZero 的双刃剑:创新与不完美的结合
It's an interesting duality. On one hand, LayerZero has been celebrated as a cornerstone of interoperability, a vital piece of the "plumbing" for Web3's future, as evidenced by its recent market performance and increasing developer interest. Its promise to integrate multiple blockchains is seen by many as key to a truly global blockchain solution. Yet, the Kelp DAO incident throws a wrench into this narrative, underscoring that groundbreaking innovation, if not coupled with ironclad security, can become a liability.
这是一个有趣的二元性。一方面,LayerZero 被誉为互操作性的基石,是 Web3 未来“管道”的重要组成部分,其最近的市场表现和日益增长的开发人员兴趣就证明了这一点。许多人认为它集成多个区块链的承诺是真正的全球区块链解决方案的关键。然而,Kelp DAO 事件打破了这种说法,强调突破性创新如果不与铁定安全相结合,可能会成为一种负担。
The criticism that the 1-of-1 DVN setup is often the default for new deployments—a point raised by Kelp DAO itself—is particularly poignant. It suggests that while the industry races forward, the onus of implementing secure configurations often falls on individual projects, some of which may be ill-equipped. My two cents? The ambition for a seamlessly connected crypto world must be matched by an equally rigorous commitment to security by design, not as an afterthought. It's not enough to build the roads; we need robust guardrails too.
对于 1-of-1 DVN 设置通常是新部署的默认设置(Kelp DAO 本身提出的这一点)的批评尤其令人心酸。这表明,尽管行业不断向前发展,但实施安全配置的责任往往落在各个项目身上,其中一些项目可能装备不足。我的两分钱?无缝连接的加密世界的雄心必须与对设计安全性的同样严格的承诺相匹配,而不是事后的想法。光修路还不够,还得修路。我们也需要坚固的护栏。
Patchwork and Progress: The Industry's Swift Response
拼凑与进步:行业的迅速反应
Thankfully, the crypto community isn't one to sit idly by. The Kelp DAO exploit has spurred a commendable flurry of activity. LayerZero quickly deprecated compromised RPC nodes and announced a policy shift to stop signing messages for applications clinging to 1-of-1 configurations. USDT0, too, hit the brakes on its bridging infrastructure, signaling a proactive, if belated, response. Perhaps most encouragingly, fixing these vulnerabilities doesn't demand a full-scale protocol revamp; OApp owners can directly update DVN configurations. Wrapped Bitcoin (wBTC) is already leading the charge, transitioning away from 1-of-1 setups by April 26, 2026.
值得庆幸的是,加密社区并没有袖手旁观。 Kelp DAO 漏洞引发了一系列值得称赞的活动。 LayerZero 迅速弃用了受损的 RPC 节点,并宣布了一项政策转变,停止为坚持 1-of-1 配置的应用程序签名消息。 USDT0 也踩下了其桥接基础设施的刹车,发出了积极主动(尽管有些迟来)的反应信号。也许最令人鼓舞的是,修复这些漏洞并不需要全面修改协议; OApp 所有者可以直接更新 DVN 配置。 Wrapped Bitcoin (wBTC) 已经处于领先地位,到 2026 年 4 月 26 日将摆脱 1-of-1 设置。
Stay Nimble, Stay Secure
保持敏捷,保持安全
For the savvy investor, the message is clear: keep an eagle eye on the security configurations of your digital holdings, especially those deployed on LayerZero. Assets like USDT0, while fundamental, remain under the security microscope until their DVN configurations are fortified. The Kelp DAO hack is a potent reminder that in the wild west of crypto, decentralization without robust security isn't a recipe for freedom, but for potential fiscal fiascos. So, as the market ebbs and flows, let's all endeavor to be a little more secure, a little more vigilant, and a lot less susceptible to the next big hack. After all, a secure blockchain is a happy blockchain, right?
对于精明的投资者来说,信息很明确:密切关注您的数字资产的安全配置,尤其是部署在 LayerZero 上的安全配置。像 USDT0 这样的资产虽然很重要,但在其 DVN 配置得到强化之前仍处于安全显微镜下。 Kelp DAO 黑客事件有力地提醒我们,在加密货币的狂野西部,没有强大安全性的去中心化不是自由的良方,而是潜在的财政惨败的良方。因此,随着市场的潮起潮落,让我们都努力变得更加安全、更加警惕,并且更不易受到下一次重大黑客攻击。毕竟,安全的区块链就是快乐的区块链,对吗?
免责声明:info@kdj.com
所提供的信息并非交易建议。根据本文提供的信息进行的任何投资,kdj.com不承担任何责任。加密货币具有高波动性,强烈建议您深入研究后,谨慎投资!
如您认为本网站上使用的内容侵犯了您的版权,请立即联系我们(info@kdj.com),我们将及时删除。
-
-
-
-
-
-
-
- USDT 没收凸显伊朗石油销售,币安账户链接
- 2026-09-15 12:05:01
- 美国检察官将目标锁定为 6120 万美元的 USDT,这些 USDT 源自伊朗石油销售,涉及币安账户并揭露非法资金流动。
-
-

































