Scan to download
BTC $79,363.60 +4.70%
ETH $2,408.39 +4.33%
BNB $649.85 +2.90%
XRP $1.46 +1.64%
SOL $88.26 +2.52%
TRX $0.3289 -0.59%
DOGE $0.0980 +3.39%
ADA $0.2553 +2.71%
BCH $465.21 +4.42%
LINK $9.50 +1.04%
HYPE $41.13 +2.86%
AAVE $94.31 +2.22%
SUI $0.9736 +2.92%
XLM $0.1810 +2.20%
ZEC $328.43 +2.64%
BTC $79,363.60 +4.70%
ETH $2,408.39 +4.33%
BNB $649.85 +2.90%
XRP $1.46 +1.64%
SOL $88.26 +2.52%
TRX $0.3289 -0.59%
DOGE $0.0980 +3.39%
ADA $0.2553 +2.71%
BCH $465.21 +4.42%
LINK $9.50 +1.04%
HYPE $41.13 +2.86%
AAVE $94.31 +2.22%
SUI $0.9736 +2.92%
XLM $0.1810 +2.20%
ZEC $328.43 +2.64%

ft

LayerZero reports the KelpDAO theft incident, confirming that it only affects the rsETH configuration

LayerZero Labs released an incident report stating that KelpDAO suffered an attack resulting in a loss of approximately $290 million. Preliminary assessments indicate that the attacker is the Lazarus Group, which has ties to North Korea (more specifically, TraderTraitor). The attack was executed by poisoning the downstream RPC infrastructure relied upon by its decentralized verification network (DVN). The attacker controlled some RPC nodes and, in conjunction with a DDoS attack, induced the system to switch to malicious nodes, thereby forging cross-chain transactions.All affected RPC nodes have been taken offline and replaced, and the DVN has now resumed operation. LayerZero emphasized that this incident was limited to the rsETH application configuration of KelpDAO and did not affect other assets or applications. The reason is that KelpDAO was using a single DVN (1/1) architecture at the time and did not utilize the multi-DVN redundancy mechanism that is officially recommended for long-term use, resulting in a lack of independent verification nodes to identify forged messages.LayerZero pointed out that there were no vulnerabilities in its protocol itself, and applications with multi-DVN configurations were not affected, meaning there is no contagious risk in the system. LayerZero stated that it will urge all projects using single DVN configurations to migrate to multi-DVN architectures as soon as possible and has suspended providing signature and verification services for 1/1 configuration applications. Meanwhile, the company is cooperating with global law enforcement agencies to investigate and assist industry partners in tracking the stolen funds. LayerZero noted that this incident highlights the value of modular security architecture and also reminds the industry to pay attention to the potential security risks of RPC verification links.

The consultation on the draft "Financial Law" has ended, with very little involvement regarding the legal status of digital currencies and the regulatory boundaries of crypto assets

According to Caixin, the one-month public consultation for the "Financial Law of the People's Republic of China (Draft)" ended today (April 19). This is the first overarching law in China and the world with "finance" in its name. The expansion of "quasi-judicial powers" for financial regulation is a topic of great concern in the market.According to Article 55 and related provisions, financial regulatory authorities have the right to access and copy property rights information, communication records, and transaction records of relevant entities and individuals when investigating financial violations. They can directly freeze or seal assets if there is evidence suggesting the transfer or concealment of illegal funds and securities. They can even decide that individuals suspected of violations cannot leave the country during the investigation.In addition, Zeng Gang, chief expert and director of the Shanghai Financial and Development Laboratory, believes that the "Financial Law" should also strengthen its focus and coverage on emerging financial formats. Topics such as AI-driven financial decision-making, the legal status of digital currencies, and the regulatory boundaries of crypto assets have sparked widespread controversy globally, but the draft addresses them very little. How to maintain a dynamic balance between lawful regulation and inclusive innovation is a problem left to be solved by legislation.
app_icon
ChainCatcher Building the Web3 world with innovations.