Cardano Founder Warns KelpDAO Hack Exposes Ethereum’s Weakest Link

bitcoinistОпубликовано 2026-04-22Обновлено 2026-04-22

Введение

Cardano founder Charles Hoskinson argues that the $292 million KelpDAO exploit reveals a critical systemic flaw in Ethereum's DeFi ecosystem, rather than just a simple bridge failure. He emphasizes that the core issue was not a smart contract vulnerability, but a failure in cross-chain message verification. Specifically, a single-verifier setup allowed a forged message to be accepted, leading to the theft of 116,500 rsETH. Hoskinson warns that the attack’s true danger emerged when the stolen assets were used as collateral in lending markets, creating widespread bad debt contagion and triggering a liquidity crisis that caused up to $13 billion in withdrawals across multiple protocols. He calls for a broader industry discussion on bridge security and verifier design to prevent similar systemic risks.

Cardano founder Charles Hoskinson used his latest livestream to argue that the roughly $292 million KelpDAO exploit was not just another bridge failure, but a broader warning about how Ethereum’s restaking, cross-chain messaging, and lending stack can turn a single compromise into system-wide contagion.

In Hoskinson’s telling, the April 18 attack exposed what he sees as the most fragile part of modern DeFi: not necessarily application-level smart contracts, but the verification layers and interdependencies that sit between protocols. He said the exploit, which involved about 116,500 rsETH drained from KelpDAO’s Ethereum escrow, should force a wider industry conversation about bridge trust assumptions, verifier design, and the speed at which bad collateral can spread through lending markets.

Cardano Founder Warns Of Dangerous Flaw At The Heart Of Ethereum DeFi

Rather than deliver a standard postmortem, Hoskinson said he took internal incident-report material and used AI to turn it into a website that walked viewers through the mechanics of the exploit. That structure framed his larger point: the failure, as he described it, did not begin with broken contract math inside KelpDAO itself, nor with an obvious accounting flaw at LayerZero. Instead, he said it centered on a forged cross-chain message that was accepted as legitimate and allowed funds to be released on Ethereum.

“So, this was not a smart contract issue with Kelp and this was not a smart contract issue with LayerZero, but this was a cross-chain message forgery,” Hoskinson said. “So this was something new and different.”

The Cardano founder repeatedly returned to one design choice in particular: the reported use of a one-of-one verifier configuration. In his explanation, best practice would be a multi-verifier model such as three-of-five, but KelpDAO’s setup relied on a single active DVN. That, he argued, created an unacceptable single point of failure in a system already layered with staking wrappers, restaking protocols, bridges, and lending venues.

“The failure was in the verification logic, not the application logic,” he said. “Kelp did everything right from their contracts. They’re audited. They’re working well. The application’s working well. It’s the bridge configuration.”
Hoskinson also emphasized that the industry still lacks a settled account of exactly where responsibility lies.

According to his summary, three separate root-cause analyses emerged after the exploit: one from LayerZero, one from KelpDAO, and one tied to LlamaRisk and Aave governance discussions but none fully agree. That leaves open whether the break occurred in the messaging layer, verifier setup, KelpDAO’s acceptance logic, or in the seams between them.

What made the event especially significant, in his view, was not only the theft itself but what happened next. Instead of dumping the stolen rsETH on decentralized exchanges, the attacker allegedly used it as collateral in lending markets to borrow more liquid assets. That turned an exploit into a balance-sheet problem for other protocols, leaving what Hoskinson described as poisoned collateral behind.

He called that dynamic the real novelty of the incident. “It wasn’t just a bridge hack. It spread to lending which then created bad debt contagion inside these lending protocols. It created a bank run and we saw $13 billion of TVL pulled in a very short period of time for a $290 million hack.”

The Cardano founder said the broader DeFi liquidity shock reached far beyond KelpDAO itself. Citing public reporting referenced in his walkthrough, he pointed to at least nine directly affected protocols and said Aave alone saw between $6.6 billion and $8.45 billion in losses, while rsETH traded in a volatile range between about $1,600 and $2,500 during the 24 hours following the attack.

He also raised the possibility of Lazarus involvement, though he acknowledged attribution remains unconfirmed. “There’s a lot of evidence here that there’s Lazarus connections,” he said, before adding that no independent forensics firms had definitively proven it.

At press time, Cardano (ADA) traded at $0.2504.

Cardano hovers below key resistance, 1-monthly chart | Source: ADAUSDT on TradingView.com

Связанные с этим вопросы

QWhat did Charles Hoskinson argue was the broader warning exposed by the KelpDAO exploit?

AHe argued that the exploit was a broader warning about how Ethereum's restaking, cross-chain messaging, and lending stack can turn a single compromise into system-wide contagion.

QAccording to Hoskinson, what was the specific technical failure that led to the KelpDAO exploit?

AThe failure was a cross-chain message forgery that was accepted as legitimate, not a smart contract issue with KelpDAO or LayerZero.

QWhat dangerous design choice did Hoskinson specifically criticize in the system's setup?

AHe criticized the use of a one-of-one verifier configuration, arguing that a multi-verifier model (like three-of-five) is a best practice to avoid a single point of failure.

QHow did the attacker allegedly use the stolen rsETH to create a wider contagion in the DeFi ecosystem?

AInstead of dumping it, the attacker used the stolen rsETH as collateral in lending markets to borrow more liquid assets, which turned the exploit into a balance-sheet problem and created bad debt contagion for other protocols.

QWhat was the estimated total value locked (TVL) that was pulled from protocols following the hack, according to Hoskinson's account?

AApproximately $13 billion of TVL was pulled in a very short period of time following the $290 million hack.

Похожее

70% of the Public Opposes AI, Americans Hope the U.S. Loses the AI War

70% of Americans believe AI development is moving too fast, with growing public resistance evolving from online criticism to real-world protests and violence. This widespread anti-AI sentiment stems from fears of job losses, rising utility costs, environmental damage, threats to democracy, and financial instability. Key incidents illustrate the backlash: Google's former CEO Eric Schmidt was loudly booed at a graduation for promoting AI; AI company ads are vandalized; protests and even violent attacks target AI firms and data centers. Polls show deep public pessimism and strong local opposition to data center construction, often surpassing resistance to nuclear power plants. The core grievances are economic and practical: AI is seen as automating jobs, concentrating wealth, and increasing household electricity and water bills due to massive data center resource demands. Environmentalists also oppose AI's high energy use and carbon emissions. This opposition has turned AI into a major political issue in the US. While the Trump administration prioritizes AI innovation for global competition, bipartisan pushback is growing. Democrats and factions within the MAGA movement are forming temporary alliances to support stricter regulations and local bans on new data centers, pressuring the administration to choose between its tech industry backers and its voter base. The situation highlights a profound national divide over AI's future.

marsbit13 мин. назад

70% of the Public Opposes AI, Americans Hope the U.S. Loses the AI War

marsbit13 мин. назад

Agents Take Over Traffic Distribution Power: What Are Tencent, ByteDance, and Alibaba Competing For?

In the race to dominate the AI era's entry point, China's tech giants—Tencent, ByteDance, and Alibaba—are aggressively deploying AI Agents to control the future of traffic distribution. Alibaba is pursuing a dual-track "closed loop + openness" strategy. Its Qianwen app is evolving into a super-Agent integrated across its ecosystem (Taobao, Alipay, etc.) to handle complex tasks like travel planning. Concurrently, it is opening its platform to external brands (Luckin Coffee, KFC) and has launched a B2B Agent platform, "Wukong," targeting enterprise automation. Its other flagship, Quark, aims to be an "AI super search box" for information and tasks. ByteDance is executing an omnipresent "sprawl strategy." Its Doubao app boasts over 300 million monthly active users and is evolving into a default AI entry point for daily life, with plans for paid versions and e-commerce integration. Its core weapon is the Kouzi platform, a visual "AI assembly factory" for developers to build custom Agents. ByteDance is also pushing hardware integration, collaborating on AI phones and developing smart glasses to embed Doubao everywhere. Tencent is playing its long-held "ultimate card" by quietly embedding an AI Agent directly into WeChat. This Agent, accessible via a swipe, can understand user commands and automatically execute tasks by calling upon WeChat's millions of mini-programs (e.g., finding and ordering coffee). This leverages WeChat's unparalleled 1.4-billion-user ecosystem to position the app as an AI-powered "service operating system," a move that could dramatically reshape the competitive landscape. The core battleground is shifting from competing for "user screen time" to competing to be the "default execution layer" for user intent. The business model is evolving from an "attention economy" to an "intent economy," where the Agent that can most efficiently fulfill a user's need gains control over service access and token flow. This represents a fundamental change in how users connect with digital services, making the fight for the Agent入口 (entry point) a pivotal moment for redefining industry leadership in the AI age.

marsbit2 ч. назад

Agents Take Over Traffic Distribution Power: What Are Tencent, ByteDance, and Alibaba Competing For?

marsbit2 ч. назад

Торговля

Спот
Фьючерсы

Популярные статьи

Как купить S

Добро пожаловать на HTX.com! Мы сделали приобретение Sonic (S) простым и удобным. Следуйте нашему пошаговому руководству и отправляйтесь в свое крипто-путешествие.Шаг 1: Создайте аккаунт на HTXИспользуйте свой адрес электронной почты или номер телефона, чтобы зарегистрироваться и бесплатно создать аккаунт на HTX. Пройдите удобную регистрацию и откройте для себя весь функционал.Создать аккаунтШаг 2: Перейдите в Купить криптовалюту и выберите свой способ оплатыКредитная/Дебетовая Карта: Используйте свою карту Visa или Mastercard для мгновенной покупки Sonic (S).Баланс: Используйте средства с баланса вашего аккаунта HTX для простой торговли.Третьи Лица: Мы добавили популярные способы оплаты, такие как Google Pay и Apple Pay, для повышения удобства.P2P: Торгуйте напрямую с другими пользователями на HTX.Внебиржевая Торговля (OTC): Мы предлагаем индивидуальные услуги и конкурентоспособные обменные курсы для трейдеров.Шаг 3: Хранение Sonic (S)После приобретения вами Sonic (S) храните их в своем аккаунте на HTX. В качестве альтернативы вы можете отправить их куда-либо с помощью перевода в блокчейне или использовать для торговли с другими криптовалютами.Шаг 4: Торговля Sonic (S)С легкостью торгуйте Sonic (S) на спотовом рынке HTX. Просто зайдите в свой аккаунт, выберите торговую пару, совершайте сделки и следите за ними в режиме реального времени. Мы предлагаем удобный интерфейс как для начинающих, так и для опытных трейдеров.

1.4k просмотров всегоОпубликовано 2025.01.15Обновлено 2026.06.02

Как купить S

Sonic: Обновления под руководством Андре Кронье – новая звезда Layer-1 на фоне спада рынка

Он решает проблемы масштабируемости, совместимости между блокчейнами и стимулов для разработчиков с помощью технологических инноваций.

2.3k просмотров всегоОпубликовано 2025.04.09Обновлено 2025.04.09

Sonic: Обновления под руководством Андре Кронье – новая звезда Layer-1 на фоне спада рынка

HTX Learn: Пройдите обучение по "Sonic" и разделите 1000 USDT

HTX Learn — ваш проводник в мир перспективных проектов, и мы запускаем специальное мероприятие "Учитесь и Зарабатывайте", посвящённое этим проектам. Наше новое направление .

1.8k просмотров всегоОпубликовано 2025.04.10Обновлено 2025.04.10

HTX Learn: Пройдите обучение по "Sonic" и разделите 1000 USDT

Обсуждения

Добро пожаловать в Сообщество HTX. Здесь вы сможете быть в курсе последних новостей о развитии платформы и получить доступ к профессиональной аналитической информации о рынке. Мнения пользователей о цене на S (S) представлены ниже.

活动图片