Chainshorts
Security

Certik Analyst: KelpDAO Exploit Reveals High-Stakes Shift in Cross-Chain Cybercrime

Certik Analyst: KelpDAO Exploit Reveals High-Stakes Shift in Cross-Chain Cybercrime

Certik analyst Wenzhao Dong reported a KelpDAO exploit linked to Lazarus Group, highlighting a shift in cross-chain cybercrime. Attackers routed activity through Aave, transferring risk onto lending protocols. The incident underscores evolving threats in DeFi, with 30,766 ETH frozen by the Arbitrum Security Council on April 18, illustrating increased security concerns in cross-chain protocols.

Read to earn +1
Share on XShare on Telegram

More in Security

Security

Mustang Panda’s New LOTUSLITE Variant Targets India Banks, South Korea Policy Circles

Cybersecurity researchers have identified a new LOTUSLITE malware variant, linked to Mustang Panda, targeting Indian banks and South Korean policy circles. The malware communicates with a dynamic DNS-based command-and-control server over HTTPS, supporting remote shell access, file operations, and session management. This indicates ongoing espionage efforts focused on sensitive financial and governmental sectors.

The Hacker NewsApr 22source ↗
Security

IRGC gunboat attacks container ship off Oman amid ceasefire extension

In a security incident on April 22, 2026, an IRGC gunboat attacked a container ship off Oman, undermining diplomatic efforts and escalating regional tensions. The attack occurred amid an ongoing ceasefire extension between the US and Iran, complicating prospects for a lasting agreement. The incident highlights ongoing security challenges in the region, impacting maritime safety and diplomatic negotiations.

Crypto BriefingApr 22source ↗
Security

Another DeFi protocol loses millions in hack days after KelpDAO breach

Volo Protocol lost approximately $3.5 million in a recent hack, days after KelpDAO was breached. The attack targeted three vaults holding WBTC, XAU, and USDC, highlighting ongoing security vulnerabilities in DeFi protocols. The incident underscores the persistent risks in the decentralized finance space, with security breaches causing significant financial losses for users and developers alike.

CoinDeskApr 22source ↗
Security

Schwartz Compares Arbitrum's Emergency to Bitcoin's 2010 Bug

Ripple CTO David Schwartz compared Arbitrum's emergency response to Bitcoin’s 2010 bug, defending the decision to freeze over 30,000 ETH linked to the KelpDAO exploit. The Arbitrum Security Council took this action on April 20, 2026, to mitigate potential damage, drawing parallels to Bitcoin’s early security measures. The move has sparked debate over security versus decentralization.

U.TodayApr 22source ↗
All Security