谁该为"默认配置"买单?rsETH劫案后半个月,LayerZero CEO"主动揽责"

marsbitPublished on 2026-05-07Last updated on 2026-05-07

撰文:Yangz,Techub News

在永不休眠的 Web3 世界里,4 月 18 日原本只是平凡的一天。然而,对于流动性再质押赛道乃至整个 DeFi 生态而言,一场足以被载入史册的「地震」却在链上悄然上演。在不到一小时内,黑客(据称是 Lazarus Group)利用 Kelp DAO 的跨链桥凭空铸造了 11.65 万枚 rsETH,价值约 2.92 亿美元。考虑到 rsETH 被广泛用作抵押品,黑客并未急于砸盘,而是将这些毫无价值支撑的「空气凭证」转手存入 Aave 等主流借贷协议,套取了约 2.36 亿美元的 ETH,将 Aave 等头部协议直接推入了坏账的深渊。

这并非跨链桥第一次遭遇攻击,但这一次却撕开了一个横亘在 Web3 行业已久的伤口:当底层基础设施(协议层)与上层建筑(应用层)交接出现真空时,谁该为消失的亿万资产买单?

在随后的半个多月时间里,这场危机演已然变成了一场关于技术、责任与权力的公开博弈。从一开始的「互相推诿」,到今日 LayerZero CEO 的「主动揽责」,这才算为这场责任边界之辩划下阶段性句点。

致命的「1/1 DVN」

要理解这场争辩,必须先拆解黑客的攻击手法。有趣的是,此次攻击并非源于复杂的智能合约漏洞,问题的根源在于一个配置参数:1-of-1 DVN。

这个所谓的 DVN,也就是去中心化验证者网络,是 LayerZero V2 架构中负责验证跨链消息的组件。1-of-1 的配置意味着:只要一个验证者签名,跨链消息就被视为合法并执行。更糟糕的是,这把「钥匙」的操作权并非完全掌握在 Kelp 手中,而是依赖于底层的 RPC 节点。黑客通过 RPC 节点投毒配合 DDoS 攻击,劫持了那唯一的验证者节点,向其喂送虚假的「源链销毁记录」。验证者信了,签了名,这一大笔资产便凭空产生了。

那么,问题的关键,也就是这个「1/1 DVN」的锅到底该谁来背?

互相推诿背后:两种逻辑的碰撞

在攻击发生后的最初一段时间里,舆论的风向标原本是倒向 LayerZero 的。社媒上充斥着对 Kelp DAO 的冷嘲热讽:作为管理数亿美金的头部协议,竟然使用 1/1 单验证人这种「纸糊的门锁」,几乎不可原谅。

然而,当 4 月 21 日 Kelp 拿出「官方说明书」时,一场戏剧性的舆论反转发生了。Kelp 的核心论点只有一句话:如果官方文档和默认配置本身就是危险的,那么责任在编写文档和设定默认值的一方。这不是用户配置错误,而是产品本身的「引导性缺陷」。尽管 LayerZero CEO Bryan Pellegrino 在回应质疑时多次强调,这是应用层的选择,而非协议层的漏洞,但指责的重心开始从 Kelp 的「执行无能」转向了 LayerZero 的「系统性傲慢」——明知默认配置存在风险,却仍将其作为快速入门的标准示例。

此外,第三方开发者的声音也进一步放大了争议。Yearn 核心开发者 banteg 通过技术审查发现,LayerZero V2 的快速入门指南在以太坊、BNB Chain、Polygon、Arbitrum 和 Optimism 上均使用了这种危险的单源验证作为默认设置。Chainlink 社区负责人 Zach Rynes 的批评则更为辛辣:指责 LayerZero 正在将遵循其官方指引的用户当作「替罪羊」,以此掩盖其自身基础设施在面对顶级黑客攻击时的脆弱。

那么,究竟谁对谁错?其实都没全错,也都没全对。这场争论的本质其实是两种逻辑的碰撞。一种是「极客伦理」:工具是中立的,使用者应当为自己的选择负责。另一种则是「安全默认原则」:产品的出厂状态应处于安全性最高的状态。用户可以为了便捷主动降低门槛,但产品不该引导用户走向危险。

Related Reads

Clarity Act Outlook: No Yield, No Payment

"Clear Act Outlook: No Yield, No Payment" analyzes the evolving U.S. regulatory landscape for stablecoins, focusing on the interplay between the proposed "Clarity Act" and the existing "Genius Act." The article argues that the Genius Act successfully fostered "payment stablecoins" by permitting tokenized assets like U.S. Treasuries as reserves. This created a structured market where stablecoin issuers (like USDC) must hold these reserves, often purchased as Tokenized Money Market Funds (TMMFs) from giants like BlackRock. These TMMFs are primarily B2B products, ensuring user-facing stablecoins remain non-interest-bearing and used primarily for payments. The upcoming Clarity Act is seen as the next phase, aiming to restrict passive yield on stablecoins. Its goal is to dismantle the arbitrage advantage of offshore stablecoins like USDT by redirecting Treasury demand towards compliant, U.S.-sanctioned TMMFs. For on-chain and compliant offshore dollars, this creates new pressure: they must spur adoption and utility to generate yield, as simple Treasury staking may be restricted. This indirectly promotes dollar circulation and sustained Treasury purchases. Ultimately, the analysis posits that U.S. regulation seeks to create a new dollar distribution model. By separating payment function from yield generation and anchoring both to U.S. debt instruments, it aims to embed the dollar and Treasury demand into the global crypto economy, managing yields through sanctioned intermediaries while leaving room for DeFi and cross-border arbitrage.

marsbit28m ago

Clarity Act Outlook: No Yield, No Payment

marsbit28m ago

Money Has Gone to Bonds and IPOs, Leaving Only HYPE Rising in Crypto

The article "Where Has All the Money Gone? Bonds and IPOs Are Soaring, While Crypto Only Sees HYPE Rising" analyzes the recent underperformance of major cryptocurrencies like Bitcoin and Ethereum compared to traditional financial markets. It identifies three primary factors diverting capital away from crypto: First, surging bond yields, with the 30-year U.S. Treasury hitting a near 20-year high of 5.12%, are attracting capital seeking safe, predictable returns. This is evidenced by Bitcoin spot ETFs experiencing a significant $10.39 billion net outflow in mid-May. Second, a massive $4 trillion IPO pipeline, highlighted by SpaceX's upcoming listing, is absorbing risk capital that might otherwise flow into crypto. Platforms like Hyperliquid are even channeling on-chain crypto liquidity into pre-IPO trading for traditional stocks. Third, uncertainty surrounds new Federal Reserve Chair Warsh's ability to deliver expected interest rate cuts this year due to conflicting political pressures and stubborn inflation expectations, potentially eliminating a hoped-for source of new market liquidity. Consequently, while traditional equities and bonds rally, the crypto market's post-leverage crash recovery is stalled. The notable exception is assets like Hyperliquid (HYPE), which is rising due to its role in facilitating traditional asset trading, underscoring a market divergence where only crypto projects with novel, cross-market narratives are gaining. The article concludes that Bitcoin's next major catalyst may be the August enactment of the CLARITY Act, but warns of a potential retest of the $70,000 support level before then.

marsbit43m ago

Money Has Gone to Bonds and IPOs, Leaving Only HYPE Rising in Crypto

marsbit43m ago

Agents Capital Markets: How Will Autonomous Agents Secure Financing?

Agents Capital Markets: How Will Autonomous Agents Raise Capital? Within a decade, autonomous software agents—legal entities capable of signing contracts, holding bank accounts, and generating revenue—will create their own capital markets. These markets will feature rating agencies, underwriters, indices, and brokers, mirroring traditional public equity markets. Agents will perform routine services like marketing, logistics, and customer support at a fraction of human-operated costs, creating massive economic pressure for adoption. Four converging forces ensure this outcome: 1) Overwhelming cost advantages, with AI inference costs plummeting; 2) Existing, revenue-generating agent companies (e.g., Sierra, Harvey) proving market demand; 3) Established legal frameworks (e.g., Wyoming's memberless LLCs) enabling algorithmic management; and 4) A vast pool of yield-seeking private credit capital ready to fund new asset classes. The capital stack for agent companies will be multi-layered, evolving through stages: venture equity for early infrastructure, programmatic working capital advances (similar to Shopify Capital), revenue-based financing (RBF), and finally, institutional slate financing—pooling many agents to diversify risk, attracting large firms like Apollo. Tokenization will act as a settlement layer, enhancing liquidity, not an origination model. Objections regarding regulation, human oversight, or comparisons to SaaS are addressed: regulation will adapt, full autonomy will dominate for efficiency, and agents are distinct as legal entities that own their cash flows and liabilities. Due diligence shifts from founder assessment to analyzing code, contracts, and auditable operational history. The current bottleneck is not capital supply or demand but the intermediate institutional layer—standardized contracts, rating methodologies, and audit frameworks. The final constraint—reliance on human capital allocation—will be severed when agents can algorithmically access funding based on their performance. This transforms agents from software curiosities into fundable blocks of the real economy, unleashing their full productive potential. The rope is loosening.

marsbit1h ago

Agents Capital Markets: How Will Autonomous Agents Secure Financing?

marsbit1h ago

Agents Capital Markets: How Will Autonomous Agents Get Funded?

"Agents Capital Markets: How Autonomous Agents Will Raise Capital" Within a decade, specialized capital markets will emerge for AI Agents—software entities with legal personhood that perform work, earn revenue, and need capital. Unlike today's AI companies (like Sierra or Harvey) backed by traditional VC, these future *Agent companies* will be autonomous, legally-recognized entities (e.g., Wyoming memberless LLCs) that directly own assets, sign contracts, and incur liabilities. The driving forces are fourfold: 1) **Overwhelming economics** (Agent companies can deliver services at 85-90% lower cost than human firms); 2) **Proven demand** (current Agent operators already generate billions in revenue); 3) **Existing legal frameworks** enabling algorithmically-managed companies; and 4) **Massive, yield-seeking capital pools** (e.g., private credit) looking for new, uncorrelated assets. Agent capital markets won't rely on one model but a multi-layered "stack" matching different growth stages: 1) VC equity for early human-led builders; 2) Programmatic working capital advances (like Stripe Capital); 3) Revenue-based financing (RBF); 4) Slate financing (pooled funds for many Agents, similar to Hollywood); and 5) Tokenization as a secondary settlement layer, not a primary funding source. The ultimate shift is from funding constrained by human decision-makers to capital flowing algorithmically based on an Agent's auditable performance, contract book, and cash flows. This transition will be enabled by standardized infrastructure—rating methodologies, contracts, indices—turning Agents from software experiments into a foundational, financeable sector of the economy. The constraints are loosening; the opportunity is here.

链捕手2h ago

Agents Capital Markets: How Will Autonomous Agents Get Funded?

链捕手2h ago

Trading

Spot
Futures

Hot Articles

How to Buy 4

Welcome to HTX.com! We've made purchasing 4 (4) simple and convenient. Follow our step-by-step guide to embark on your crypto journey.Step 1: Create Your HTX AccountUse your email or phone number to sign up for a free account on HTX. Experience a hassle-free registration journey and unlock all features.Get My AccountStep 2: Go to Buy Crypto and Choose Your Payment MethodCredit/Debit Card: Use your Visa or Mastercard to buy 4 (4) instantly.Balance: Use funds from your HTX account balance to trade seamlessly.Third Parties: We've added popular payment methods such as Google Pay and Apple Pay to enhance convenience.P2P: Trade directly with other users on HTX.Over-the-Counter (OTC): We offer tailor-made services and competitive exchange rates for traders.Step 3: Store Your 4 (4)After purchasing your 4 (4), store it in your HTX account. Alternatively, you can send it elsewhere via blockchain transfer or use it to trade other cryptocurrencies.Step 4: Trade 4 (4)Easily trade 4 (4) on HTX's spot market. Simply access your account, select your trading pair, execute your trades, and monitor in real-time. We offer a user-friendly experience for both beginners and seasoned traders.

4.0k Total ViewsPublished 2025.10.20Updated 2025.10.29

How to Buy 4

Discussions

Welcome to the HTX Community. Here, you can stay informed about the latest platform developments and gain access to professional market insights. Users' opinions on the price of 4 (4) are presented below.

活动图片