Scan to download
BTC $60,639.61 -3.32%
ETH $1,558.39 -6.96%
BNB $574.11 -3.30%
XRP $1.08 -4.36%
SOL $62.00 -6.50%
TRX $0.3189 -2.18%
DOGE $0.0804 -5.00%
ADA $0.1549 -5.17%
BCH $220.13 -4.27%
LINK $7.27 -4.14%
HYPE $58.85 -3.46%
AAVE $60.75 -9.85%
SUI $0.6949 -3.14%
XLM $0.1953 +1.74%
ZEC $366.07 +6.59%
BTC $60,639.61 -3.32%
ETH $1,558.39 -6.96%
BNB $574.11 -3.30%
XRP $1.08 -4.36%
SOL $62.00 -6.50%
TRX $0.3189 -2.18%
DOGE $0.0804 -5.00%
ADA $0.1549 -5.17%
BCH $220.13 -4.27%
LINK $7.27 -4.14%
HYPE $58.85 -3.46%
AAVE $60.75 -9.85%
SUI $0.6949 -3.14%
XLM $0.1953 +1.74%
ZEC $366.07 +6.59%

bridge

Aave releases post-attack investigation on Kelp rsETH bridge

Regarding the attack on the Kelp rsETH LayerZero V2 bridge that occurred on April 18, Aave released a post-incident investigation on the X platform, emphasizing that the exposure was primarily due to third-party bridge infrastructure rather than the protocol itself. The attacker executed an RPC poisoning attack targeting a single validator of LayerZero, forging a cross-chain message. This led to the release of 116,500 rsETH on the Ethereum side without actual destruction on Unichain. The attacker subsequently deposited the stolen rsETH into Aave V3 (Ethereum Core and Arbitrum), borrowing approximately 82,650 WETH and 821 wstETH.The Aave Protocol Guardian and Risk Steward immediately implemented protective measures for the rsETH and WETH reserves. Currently, the WETH and rsETH markets in the affected V3 deployments are operating normally. The rsETH held by the attacker on Arbitrum has been destroyed, the LayerZero OFT adapter has been fully recharged in five batches, rsETH support has been fully restored, and Kelp has reopened the withdrawal, bridging, and claims functions for rsETH. The WETH LTV in the affected markets has been reset to pre-attack values, and Aave V3 is fully operational across all markets except for rsETH.The Arbitrum DAO has voted to authorize the transfer of frozen ETH to Aave LLC, and it is currently awaiting on-chain execution. The court is still reviewing the substantive content of the injunction, and Aave LLC will continue to comply with the injunction during the court's deliberation. Ongoing projects include: the Aave risk framework from Llama Risk, the bridging assessment framework, the release of evaluation reports for currently live assets, on-chain execution of Arbitrum DAO votes, and the court's review of the injunction.

TAC: About 90% of the stolen assets have been recovered, and the cross-chain bridge will resume operation after the audit is completed

The TON Network expansion project TAC has disclosed that a security incident occurred with the TON-TAC asset bridge on May 11. Four days later, approximately 80% of the affected assets have been returned. TAC today released a post-incident analysis report detailing the events. The root cause of the vulnerability was a lack of a single verification in the sorter software: the attacker deployed a counterfeit Jetton wallet on TON, and the sorter accepted the counterfeit tokens because it did not verify the code hash of the sender's wallet. The total loss was approximately $2.86 million, involving USDT, BLUM, and tsTON. Following a public appeal, about 90% of the assets were returned to the multi-signature address controlled by TAC on May 14, with the remaining 10% retained by the attacker.The cross-chain bridge remains paused, awaiting independent review of the repaired sorter software by the auditing party and TON partners. Cross-chain operations will resume once the verification of the repaired software is completed and the gap is filled with recovered assets and TAC Foundation token reserves. Due to the need for multi-party coordination, a precise timeline cannot be provided. The remaining funding gap will be filled by the TAC Foundation treasury, ensuring that users and protocols incur no financial losses. TAC reminds users that official updates are only published through this account and Telegram, and any unsolicited "recovery" or "support" private messages are scams.
app_icon
ChainCatcher Building the Web3 world with innovations.