谁该为"默认配置"买单?rsETH劫案后半个月,LayerZero CEO"主动揽责"

marsbitОпубліковано о 2026-05-07Востаннє оновлено о 2026-05-07

撰文:Yangz,Techub News

在永不休眠的 Web3 世界里,4 月 18 日原本只是平凡的一天。然而,对于流动性再质押赛道乃至整个 DeFi 生态而言,一场足以被载入史册的「地震」却在链上悄然上演。在不到一小时内,黑客(据称是 Lazarus Group)利用 Kelp DAO 的跨链桥凭空铸造了 11.65 万枚 rsETH,价值约 2.92 亿美元。考虑到 rsETH 被广泛用作抵押品,黑客并未急于砸盘,而是将这些毫无价值支撑的「空气凭证」转手存入 Aave 等主流借贷协议,套取了约 2.36 亿美元的 ETH,将 Aave 等头部协议直接推入了坏账的深渊。

这并非跨链桥第一次遭遇攻击,但这一次却撕开了一个横亘在 Web3 行业已久的伤口:当底层基础设施(协议层)与上层建筑(应用层)交接出现真空时,谁该为消失的亿万资产买单?

在随后的半个多月时间里,这场危机演已然变成了一场关于技术、责任与权力的公开博弈。从一开始的「互相推诿」,到今日 LayerZero CEO 的「主动揽责」,这才算为这场责任边界之辩划下阶段性句点。

致命的「1/1 DVN」

要理解这场争辩,必须先拆解黑客的攻击手法。有趣的是,此次攻击并非源于复杂的智能合约漏洞,问题的根源在于一个配置参数:1-of-1 DVN。

这个所谓的 DVN,也就是去中心化验证者网络,是 LayerZero V2 架构中负责验证跨链消息的组件。1-of-1 的配置意味着:只要一个验证者签名,跨链消息就被视为合法并执行。更糟糕的是,这把「钥匙」的操作权并非完全掌握在 Kelp 手中,而是依赖于底层的 RPC 节点。黑客通过 RPC 节点投毒配合 DDoS 攻击,劫持了那唯一的验证者节点,向其喂送虚假的「源链销毁记录」。验证者信了,签了名,这一大笔资产便凭空产生了。

那么,问题的关键,也就是这个「1/1 DVN」的锅到底该谁来背?

互相推诿背后:两种逻辑的碰撞

在攻击发生后的最初一段时间里,舆论的风向标原本是倒向 LayerZero 的。社媒上充斥着对 Kelp DAO 的冷嘲热讽:作为管理数亿美金的头部协议,竟然使用 1/1 单验证人这种「纸糊的门锁」,几乎不可原谅。

然而,当 4 月 21 日 Kelp 拿出「官方说明书」时,一场戏剧性的舆论反转发生了。Kelp 的核心论点只有一句话:如果官方文档和默认配置本身就是危险的,那么责任在编写文档和设定默认值的一方。这不是用户配置错误,而是产品本身的「引导性缺陷」。尽管 LayerZero CEO Bryan Pellegrino 在回应质疑时多次强调,这是应用层的选择,而非协议层的漏洞,但指责的重心开始从 Kelp 的「执行无能」转向了 LayerZero 的「系统性傲慢」——明知默认配置存在风险,却仍将其作为快速入门的标准示例。

此外,第三方开发者的声音也进一步放大了争议。Yearn 核心开发者 banteg 通过技术审查发现,LayerZero V2 的快速入门指南在以太坊、BNB Chain、Polygon、Arbitrum 和 Optimism 上均使用了这种危险的单源验证作为默认设置。Chainlink 社区负责人 Zach Rynes 的批评则更为辛辣:指责 LayerZero 正在将遵循其官方指引的用户当作「替罪羊」,以此掩盖其自身基础设施在面对顶级黑客攻击时的脆弱。

那么,究竟谁对谁错?其实都没全错,也都没全对。这场争论的本质其实是两种逻辑的碰撞。一种是「极客伦理」:工具是中立的,使用者应当为自己的选择负责。另一种则是「安全默认原则」:产品的出厂状态应处于安全性最高的状态。用户可以为了便捷主动降低门槛,但产品不该引导用户走向危险。

Пов'язані матеріали

Will Ethereum's Native Privacy Proposal EIP-8182 Absorb Liquidity from Other Privacy Coins?

The article discusses Ethereum Improvement Proposal (EIP) 8182, titled "Private ETH and ERC-20 Transfers," a draft proposal to integrate native privacy directly into the Ethereum protocol layer (L1). Currently, Ethereum transactions are fully transparent, and existing privacy solutions like Tornado Cash are third-party dApps with limitations: small anonymity sets (mixing pools), lack of interoperability, and regulatory vulnerability. EIP-8182 aims to create a large, unified "shared shielded pool" and zero-knowledge proof (ZK) precompiles within the core protocol. Key features include a massive, shared anonymity pool for all users and dApps, significantly enhancing privacy strength; native support for private transfers of ETH and any ERC-20 token; a decentralized system contract architecture without admin controls or fees; and the use of ZK proofs to validate transactions without revealing specific details. If implemented, this upgrade could position Ethereum as the world's largest privacy-focused blockchain. By offering a built-in, highly private environment with a vast user base and liquidity, it might attract institutional and individual users, potentially drawing liquidity away from dedicated privacy coins like Zcash and Monero, or even users seeking privacy on Bitcoin. The integration could transform Ethereum from a transparent public ledger into a dominant privacy-centric platform, with potential future enhancements like fully homomorphic encryption (FHE) for compliance capabilities.

marsbit6 хв тому

Will Ethereum's Native Privacy Proposal EIP-8182 Absorb Liquidity from Other Privacy Coins?

marsbit6 хв тому

Investors Frantically Snap Up AI Firms with 'No Profits': A High-Stakes Gamble on 'the Right to Define the Future'

"Investors are pouring billions into Chinese AI startups with no profits, betting on the future of the industry. A state-backed fund is reportedly in talks to lead DeepSeek's funding at a $45B valuation, just weeks after it was valued at $10B. Along with companies like Zhipu AI, MiniMax, and Kimi (backed by Meituan and Alibaba), their combined valuation exceeds $140B. This isn't a typical venture capital play. Investors are paying for 'future definition rights'—a chance to set the standards for the next tech era. Morgan Stanley notes a 6-12 month window for this scarcity premium before more AI companies go public. Despite massive losses, these companies show strong growth. Zhipu AI's API revenue grew 60x, Kimi's annual recurring revenue doubled to $200M in a month, and MiniMax turned its gross margin positive, with over 70% of revenue from overseas. Their valuations vastly exceed profitable firms like iFlytek. Crucially, technical progress underpins this growth. DeepSeek's latest model boasts costs just 1% of a leading competitor's, while Zhipu AI has raised API prices due to high demand. However, gaps with top global models remain. Tech giants like Tencent and Alibaba, investing heavily while describing their own AI efforts as 'leaky boats,' are also investing in these startups as a hedge. Key risks loom: the closing scarcity window, computing power bottlenecks limiting growth, and the sustainability of DeepSeek's cost-advantage model. With state capital now a major player, the success of these companies has become a strategic national concern. The next year will test if their soaring valuations can be justified by future profits."

marsbit56 хв тому

Investors Frantically Snap Up AI Firms with 'No Profits': A High-Stakes Gamble on 'the Right to Define the Future'

marsbit56 хв тому

SEC Slams the Brakes at the Last Minute, Halting "Tokenized U.S. Stocks"

On May 22, the U.S. SEC postponed the release of a key "innovation exemption" draft that would have permitted crypto-native platforms to issue and trade tokenized U.S. stocks on decentralized venues without full traditional exchange compliance. This would have legalized a "third-party token" model used overseas, where platforms issue tokens tracking stock prices without the underlying company's involvement, raising unresolved questions about shareholder rights, dividends, and sanctions enforcement. Meanwhile, the SEC had already approved a different, compliant path for tokenization led by Nasdaq and NYSE. Their model integrates tokenized stocks into existing settlement systems (like DTCC), preserving all shareholder rights. This creates a fundamental conflict: crypto platforms seek a permissionless, 24/7 on-chain parallel market, while traditional exchanges advocate for an upgraded, regulated version of the current system. Intense lobbying from traditional exchange groups like the World Federation of Exchanges argued the exemption would create an unfair regulatory advantage and dilute investor protection. Even some compliant crypto firms favored delay. Internally, SEC commissioners were divided on the scope and pace of the exemption. The delay highlights a critical policy crossroads. With significant trading volume already occurring overseas, the SEC's decision will determine whether the U.S. embraces a dual-track system for tokenized equities or sidelines itself from an emerging global infrastructure. The core unresolved question remains the legal status and rights of holders of third-party tokenized stocks. The SEC paused because the draft framework risked creating a major new asset class with profound, unanswered legal implications.

marsbit1 год тому

SEC Slams the Brakes at the Last Minute, Halting "Tokenized U.S. Stocks"

marsbit1 год тому

Is a Super IPO Wave Coming? Will It Drain and Crash the U.S. Stock Market?

The article discusses concerns about a potential "super IPO wave" hitting the U.S. stock market, with major companies like SpaceX, OpenAI, and Anthropic preparing to go public. While these large IPOs could collectively raise hundreds of billions, raising fears of a market "blood drain," analysis suggests the impact may be limited. Key points include: * Historical data shows IPO waves often coincide with strong market returns, as they typically occur during periods of high investor demand. * Model estimates suggest even the largest IPOs might only cause a market dip of around 1%. They are more likely to trigger a routine market pullback rather than end a bull market. * The current demand side remains supportive due to high household cash balances, strong corporate earnings growth, continued stock fund inflows, and robust share buyback announcements. * The main risk lies in concentrated investor positions, particularly in large-cap tech stocks, which are at elevated levels. A shift in funds towards new issuances could pressure these crowded sectors. * Recent fund flows show strength concentrated in U.S. and tech stocks, while other regions like Europe and Japan are experiencing outflows. The conclusion is that the IPO wave itself is unlikely to crash the market unless it coincides with a weakening in underlying demand factors like earnings or fund inflows into U.S. equities. The focus should be on whether demand can continue to absorb the new supply.

marsbit1 год тому

Is a Super IPO Wave Coming? Will It Drain and Crash the U.S. Stock Market?

marsbit1 год тому

Торгівля

Спот
Ф'ючерси

Популярні статті

Як купити 4

Ласкаво просимо до HTX.com! Ми зробили покупку 4 (4) простою та зручною. Дотримуйтесь нашої покрокової інструкції, щоб розпочати свою криптовалютну подорож.Крок 1: Створіть обліковий запис на HTXВикористовуйте свою електронну пошту або номер телефону, щоб зареєструвати обліковий запис на HTX безплатно. Пройдіть безпроблемну реєстрацію й отримайте доступ до всіх функцій.ЗареєструватисьКрок 2: Перейдіть до розділу Купити крипту і виберіть спосіб оплатиКредитна/дебетова картка: використовуйте вашу картку Visa або Mastercard, щоб миттєво купити 4 (4).Баланс: використовуйте кошти з балансу вашого рахунку HTX для безперешкодної торгівлі.Треті особи: ми додали популярні способи оплати, такі як Google Pay та Apple Pay, щоб підвищити зручність.P2P: Торгуйте безпосередньо з іншими користувачами на HTX.Позабіржова торгівля (OTC): ми пропонуємо індивідуальні послуги та конкурентні обмінні курси для трейдерів.Крок 3: Зберігайте свої 4 (4)Після придбання 4 (4) збережіть його у своєму обліковому записі на HTX. Крім того, ви можете відправити його в інше місце за допомогою блокчейн-переказу або використовувати його для торгівлі іншими криптовалютами.Крок 4: Торгівля 4 (4)Легко торгуйте 4 (4) на спотовому ринку HTX. Просто увійдіть до свого облікового запису, виберіть торгову пару, укладайте угоди та спостерігайте за ними в режимі реального часу. Ми пропонуємо зручний досвід як для початківців, так і для досвідчених трейдерів.

393 переглядів усьогоОпубліковано 2025.10.20Оновлено 2025.10.20

Як купити 4

Обговорення

Ласкаво просимо до спільноти HTX. Тут ви можете бути в курсі останніх подій розвитку платформи та отримати доступ до професійної ринкової інформації. Нижче представлені думки користувачів щодо ціни 4 (4).

活动图片