News: Kelp DAO suffered a $292 million crypto heist over the weekend, attributed to North Korean hackers known as 'TraderTraitor' (a Lazarus Group subunit). The attack exploited a vulnerability in LayerZero's cross-chain bridge, using AI to manipulate data nodes. Kelp DAO's single-verifier model lacked independent verification, allowing the attacker to input fraudulent transaction details. LayerZero stated they had advised against this configuration. The incident led Aave to freeze accounts to mitigate potential cascading effects. North Korea has reportedly stolen $659 million in crypto in 2024, with DeFi hacks increasingly funding state programs.
AI Analysis: The incident demonstrates the growing threat of AI-driven attacks in the DeFi space, highlighting the need for robust security measures and redundancy to prevent single points of failure. The reliance on speed over security in automated protocols presents a significant vulnerability.