COINPURO - Crypto Currency Latest News logo COINPURO - Crypto Currency Latest News logo
Crypto Potato 2026-04-20 11:29:27

DeFiLlama Co-Founder Suggests 3 Paths to Resolve $293M KelpDAO Hack Fallout

The $293 million KelpDAO hack on April 18 has left Aave, rsETH holders, and the wider DeFi ecosystem staring at a hole nobody quite knows how to fill. But on Sunday, DeFiLlama co-founder 0xngmi laid out three realistic options on the table and ran the numbers on each. Three Scenarios, None of Them Clean 0xngmi’s first option is to spread the pain. According to them, if KelpDAO socializes losses across all users, it would work out to an 18.5% haircut. There are some 666,000 rsETH sitting across Aave deployments, and most mainnet positions are looped close to the maximum loan-to-value ratio (LTV), so 0xngmi’s model assumes they are essentially at liquidation. Wiping out all equity in those positions leaves roughly $216 million in bad debt, and Aave’s Umbrella ETH coverage would absorb $55 million of that, while the protocol’s treasury could cover another $85 million, which would leave a gap of about $76 million. To close it, 0xngmi suggested that Aave could either take out a loan or liquidate its AAVE treasury tokens. That stash is currently worth around $51 million. Option two is much uglier, as it would mean “rugging” rsETH holders on layer 2 chains. This would leave Aave with $359 million of rsETH supply, and assuming it was all looped at maximum LTV, it would create $341 million of bad debt across lending markets. But since Umbrella covers none of it, 0xngmi said Aave would have to pick which markets to salvage and which to abandon, with Arbitrum, Mantle, and Base most likely to suffer the biggest losses. The third option, while most technically appealing, could be the hardest to pull off. It involves going back to a pre-hack snapshot and trying to make only the direct victims whole. This would mean paying back the $124 million the hacker is said to have taken from Aave and another $18 million from Arbitrum. But the problem is that, since the hack, the money has moved around a lot across pooled protocols, making it difficult to cleanly separate one depositor’s funds from another. OneKey founder Yishi also pushed for a fourth path that sits outside 0xngmi’s framework: negotiate with the hacker first, offering them a 10% to 15% bounty, and try to get most of the money back before any of the harder decisions need to be made. If that fails, Yishi argued that LayerZero’s ecosystem fund should carry most of the bill, given its resources and long-term interest in preserving the OFT ecosystem. How $293M Left in Two Transactions Cyvers founder Meir Dolev reconstructed the on-chain timeline for the KelpDAO attack , and it moves fast. The attacker’s wallet was funded through Tornado Cash about 10 hours before anything happened. Then, at 17:35 UTC on April 18, two transactions occurred: commitVerification on LayerZero’s ReceiveUIn302, followed 24 seconds later by IzReceive on EndpointV2. That second transaction drained 116,500 rsETH, valued at about $293.5 million, in one shot. KelpDAO’s multisig responded at 18:23 UTC by blacklisting the attacker’s recipient address on rsETH, and it worked. A second attempt, 3 minutes later, which would have taken another 40,000 rsETH worth around $100 million, hit the blacklist and reverted. According to Dolev, the root cause was quite simple: KelpDAO’s Unichain-to-Ethereum bridge required only one DVN attestation to release funds. Forging that one verification allowed the hacker to move $293 million. LayerZero also published its own statement attributing the attack to Lazarus Group’s TraderTraitor unit. The company said the protocol worked as designed and also pointed directly at KelpDAO’s 1-of-1 DVN configuration as the cause, noting it had previously recommended multi-DVN setups to all integration partners. Security researcher Andy was blunter, calling KelpDAO’s decision to run a single DVN while holding $1.5 billion in user funds “extremely irresponsible” and warning that dozens of other protocols are running the exact same setup right now. The post DeFiLlama Co-Founder Suggests 3 Paths to Resolve $293M KelpDAO Hack Fallout appeared first on CryptoPotato .

가장 많이 읽은 뉴스

coinpuro_earn
면책 조항 읽기 : 본 웹 사이트, 하이퍼 링크 사이트, 관련 응용 프로그램, 포럼, 블로그, 소셜 미디어 계정 및 기타 플랫폼 (이하 "사이트")에 제공된 모든 콘텐츠는 제 3 자 출처에서 구입 한 일반적인 정보 용입니다. 우리는 정확성과 업데이트 성을 포함하여 우리의 콘텐츠와 관련하여 어떠한 종류의 보증도하지 않습니다. 우리가 제공하는 컨텐츠의 어떤 부분도 금융 조언, 법률 자문 또는 기타 용도에 대한 귀하의 특정 신뢰를위한 다른 형태의 조언을 구성하지 않습니다. 당사 콘텐츠의 사용 또는 의존은 전적으로 귀하의 책임과 재량에 달려 있습니다. 당신은 그들에게 의존하기 전에 우리 자신의 연구를 수행하고, 검토하고, 분석하고, 검증해야합니다. 거래는 큰 손실로 이어질 수있는 매우 위험한 활동이므로 결정을 내리기 전에 재무 고문에게 문의하십시오. 본 사이트의 어떠한 콘텐츠도 모집 또는 제공을 목적으로하지 않습니다.