QooryBeta
Back to narratives
SecurityActive
Conversation intelligence

Kelp $293M Exploit via Compromised Validator

Kelp lost $293M after a compromised cross-chain message validator allowed an attacker to drain 18% of token supply. The exploit bypassed smart contract audits entirely, highlighting infrastructure-level trust risks.

Heat
99
Confidence
95%
Evidence
7
Updated

Why It Happened

The attacker compromised a validator responsible for cross-chain message verification, breaking the trust assumption that audits cannot cover. This enabled the theft of $293M without touching any smart contract code.

Outcome So Far

Funds stolen; community trust eroded; calls for velocity limits and better infrastructure security.

Actors

Timeline order

Post
Parent event 01

X conversation update

1 related posts from @CertiKAlert

Related posts@CertiKAlert
@CertiKAlert
Open on X16.5K views · 84 likes · 15 reposts

Post
Parent event 02

X conversation update

3 related posts from @secondfiapp, @Ucan_Coin, @SiCkBrAiNwAlKeR

Related posts@secondfiapp@Ucan_Coin@SiCkBrAiNwAlKeR
@secondfiapp
Open on X111.4K views · 289 likes · 83 reposts
@Ucan_Coin
Open on X9.7K views · 114 likes · 10 reposts
@SiCkBrAiNwAlKeR
Open on X7.9K views · 104 likes · 9 reposts

Post
Parent event 03

Commentary on Kelp Exploit

Ucan_Coin notes that $292M left Kelp in one motion, questioning why no velocity limits prevented 18% of token supply from being moved unchecked.

Related posts@Ucan_Coin
@Ucan_Coin
Open on X13.6K views · 139 likes · 8 reposts

Post
Parent event 04

X conversation update

1 related posts from @CertiKAlert

Related posts@CertiKAlert
@CertiKAlert
Open on X5.4K views · 44 likes · 8 reposts

Post
Parent event 05

Kelp $293M Exploit Reported

Kelp lost $293M due to a compromised cross-chain message validator. The exploit did not touch smart contract code, bypassing audits.

Related posts@0xALTF4
@0xALTF4
Open on X686 views · 26 likes · 4 reposts