🚨 The contract wasn’t hacked, yet the market froze $13 billion? One fake news report was enough.

Group: 点击进入玖玖的粉丝群

👀 Event in one sentence: A fake-message attack was carried out on the Kelp DAO cross-chain bridge, minting 116,500 uncollateralized rsETH out of thin air (about 18% of circulating supply). Total loss is estimated at $292 million, and the attack is pointed to the North Korean Lazarus hacking group.

📊 Putting the numbers in context: The stolen rsETH was used as collateral in lending markets like Aave. Multiple protocols urgently froze the rsETH market. Within two days, over $13 billion in total value locked exited DeFi. Aave’s core contracts were never touched, yet users were still affected.

🔥 What’s behind the numbers: The attacker wasn’t targeting the lending code, but the weakest link in the “trust chain”—the bridge and message verification. Halborn, a security firm, said the attackers took out honest nodes, replaced them with nodes they controlled, and then inserted a forged cross-chain packet to make it work.

💡 What’s truly worth watching isn’t that DeFi is failing—it’s that “de-trust” still depends on something: oracles, bridges, wrapped assets, governance. If any link fails, even a secure contract won’t matter. On Bitcoin, Ethereum needs to be wrapped first, adding yet another attack surface.

⚠️ A bucket of cold water: Don’t rush to praise CeFi security—Celsius and BlockFi are warnings not far off. CeFi just swaps risk from code to humans; it doesn’t eliminate risk. Risk management has never been about picking sides—it’s about seeing clearly who (or what) you’re putting your trust in.

👀 Will you place large assets in DeFi lending, or choose a centralized platform? Let’s discuss in the comments below 👇

Click the avatar to watch the livestream + join the Jiu Jiu chat group to get daily strategies 🚀
#DeFi #ETH #crypto market