Post
X conversation update
1 related posts from @CertiKAlert
Kelp lost $293M after a compromised cross-chain message validator allowed an attacker to drain 18% of token supply. The exploit bypassed smart contract audits entirely, highlighting infrastructure-level trust risks.
The attacker compromised a validator responsible for cross-chain message verification, breaking the trust assumption that audits cannot cover. This enabled the theft of $293M without touching any smart contract code.
Funds stolen; community trust eroded; calls for velocity limits and better infrastructure security.
1 related posts from @CertiKAlert
3 related posts from @secondfiapp, @Ucan_Coin, @SiCkBrAiNwAlKeR
Ucan_Coin notes that $292M left Kelp in one motion, questioning why no velocity limits prevented 18% of token supply from being moved unchecked.
1 related posts from @CertiKAlert
Kelp lost $293M due to a compromised cross-chain message validator. The exploit did not touch smart contract code, bypassing audits.