Connect with us
DAPA Banner

Crypto World

Ripple CTO Warns RLUSD Faces DeFi Bridge Security Gaps

Published

on

Crypto Breaking News

David Schwartz raised fresh concerns about integrating decentralized finance bridges for Ripple’s RLUSD stablecoin. He focused on security risks after reviewing several cross-chain systems. Besides that, his findings showed that most protocols had strong technical foundations but still faced deployment weaknesses.

However, he stressed that operational decisions often weaken security layers. Many teams prioritize ease of use and faster expansion across networks. Consequently, critical safeguards get overlooked, which increases exposure to exploits across connected chains.

Convenience Trade-Offs Create Vulnerabilities

Schwartz explained that several bridge systems discourage full use of key security features. He noted that developers avoid complex safeguards due to cost and operational challenges. Moreover, this approach creates gaps that attackers can exploit during high-value transactions.

Advertisement

Additionally, he linked this pattern to recent exploit cases in the DeFi sector. He pointed out that convenience-driven decisions reduce resilience against advanced attacks. Hence, systems that appear secure in design may fail under real-world pressure.

KelpDAO Exploit Reflects Broader Risks

The recent attack on KelpDAO involved the loss of around $292 million tied to rsETH tokens. Attackers exploited cross-chain messaging linked to LayerZero infrastructure. Significantly, the exploit relied on manipulating transaction validation processes.

On-chain data showed that about 116,500 rsETH tokens moved to attacker-controlled wallets. Moreover, the attacker used these assets as collateral on Aave V3 to borrow ETH and WETH. Consequently, the funds moved through Tornado Cash to obscure transaction trails.

Cross-Chain Weaknesses Raise RLUSD Concerns

Schwartz noted similarities between the exploit and potential risks for RLUSD integration. He suggested that ignoring LayerZero’s advanced security features may have contributed to the breach. Additionally, he described the attack as more complex than initially expected.

Advertisement

Moreover, he emphasized that cross-chain infrastructure introduces multiple points of failure. Each connection between networks increases risk exposure. Hence, stablecoin systems relying on such bridges must prioritize strict validation mechanisms.

Broader Ecosystem Flags Additional Risks

Concerns also extend to wrapped assets such as wXRP on other networks. An XRPL validator highlighted counterparty risks tied to issued tokens across chains. Besides that, ecosystem participants continue to evaluate governance changes for lending protocols.

However, some developers argue that proposed updates may not deliver strong utility for XRP holders. Meanwhile, discussions continue around collateral use cases and protocol efficiency.

Risk & affiliate notice: Crypto assets are volatile and capital is at risk. This article may contain affiliate links. Read full disclosure

Advertisement

Source link

Continue Reading
Click to comment

You must be logged in to post a comment Login

Leave a Reply

Crypto World

Aave Models $124M to $230M in Bad Debt From Kelp Exploit

Published

on

Aave Models $124M to $230M in Bad Debt From Kelp Exploit

In a detailed incident report, Aave service providers quantified the protocol’s exposure for the first time and outlined two scenarios depending on how Kelp DAO allocates the loss. LayerZero and Kelp continue to blame each other for the compromised bridge configuration.

Aave service providers on Monday published an incident report quantifying the protocol’s exposure to the April 18 Kelp DAO rsETH bridge exploit, outlining two bad-debt scenarios ranging from $123.7 million to $230.1 million, and recommending an immediate pause of the protocol’s Umbrella safety module.

According to the report, posted to the Aave governance forum, 89,567 of the 116,500 rsETH stolen from Kelp’s LayerZero bridge were deposited across seven attacker-controlled wallets on Aave. Those positions borrowed 82,650 WETH ($190.86 million) and 821 wstETH ($2.33 million).

The single largest position, on Aave’s Ethereum Core market, supplied 53,000 rsETH and borrowed 52,460 WETH, or $121 million, from one wallet. The remaining positions were distributed across Aave’s Arbitrum deployment. All attacker positions currently sit at health factors between 1.01 and 1.03.

Advertisement

Kelp subsequently recovered 40,373 rsETH by freezing a second attempted drain. That balance is the only confirmed backing for 152,577 rsETH of claims across every L2, a pro-rata backing ratio of 26.46%. Ethereum mainnet rsETH is backed separately by Kelp’s underlying ETH staking deposits.

Two bad debt scenarios

The report declined to commit to a single bad-debt figure, stating that the outcome depends on decisions outside Aave’s control — primarily how Kelp accounts for the loss and whether it updates its LRTOracle exchange rate.

Under Scenario 1, a uniform socialization across all rsETH holders on all chains, each token takes a 15.12% haircut. Total bad debt reaches $123.7 million, with the Ethereum Core WETH reserve absorbing $91.8 million, or a 1.54% shortfall. Mantle absorbs $10.4 million, or 9.54% of its WETH reserve, the most proportionally acute.

Under Scenario 2, losses are isolated to rsETH on L2s. Remote-chain rsETH is repriced to its 26.46% backing ratio, or a 73.54% haircut, while Ethereum mainnet rsETH is unaffected. Total bad debt rises to $230.1 million, all concentrated on L2s.

Advertisement

In this scenario, Mantle faces a 71.45% shortfall ($77.7 million), Arbitrum 26.67% ($88.4 million), Base 23.28% ($47.5 million), and Ink 18% ($13.9 million). Ethereum Core is untouched.

Umbrella covers only Ethereum Core reserves. Under Scenario 2, it would not activate.

Balance sheet disclosure

The report disclosed the Aave DAO’s financial position. As of April 20, the treasury holds $181 million — $62 million in Ethereum-correlated holdings, $54 million in AAVE tokens, and $52 million in stablecoins. The DAO generated $145 million in revenue in 2025 and $38 million year-to-date in 2026, with operating cash flow of $149 million in 2025 and $40 million year-to-date.

Aave DAO service providers are “leading an effort with ecosystem participants to address a potential bad-debt scenario,” the report said, and the effort has received “indicative commitments from various parties.” It did not identify the parties or quantify the commitments.

Advertisement

The report also recommended the DAO immediately pause the WETH Umbrella module. As of writing, 18,922 of the 23,507 aWETH staked in Umbrella — approximately 80% — have already entered the 20-day unstaking cooldown. A pause would block further deposits, withdrawals, transfers, and slashing. Coverage under a paused module would need to be handled manually through governance rather than automatically.

A second-order liquidation risk

The report also quantified the risk of further bad debt if ETH falls in price while Aave’s WETH reserves remain at 100% utilization. Because idle WETH balances are below $20 on every affected chain, liquidators cannot receive WETH as underlying and instead receive aWETH receipts, which keeps their capital inside the reserve and slows liquidation throughput.

At a 50% ETH price drop, Aave modeled $100.8 million of residual bad debt on Ethereum alone, with smaller amounts on Arbitrum, Base, Linea, and Mantle. Arbitrum and Base were flagged as particularly vulnerable because wstETH looping positions on those chains run at health factors around 1.03 — meaning first liquidations would trigger at ETH price drops of just 0.77% and 1.77%, respectively.

LayerZero and Kelp continue to trade blame

The Aave report did not assign blame for the underlying bridge exploit. LayerZero and Kelp DAO have continued to publicly attribute the incident to each other.

Advertisement

In a Sunday post-mortem, LayerZero Labs attributed the attack to the DPRK-linked Lazarus Group. The company said attackers compromised two downstream Remote Procedure Call (RPC) nodes used by its LayerZero-operated Decentralized Verifier Network (DVN), and introduced malicious software that returned forged data only to the DVN, then launched a DDoS attack to force failover to the poisoned RPC nodes.

LayerZero said the protocol itself was not exploited and attributed the attack’s success to Kelp’s use of a 1-of-1 DVN configuration.

In a rebuttal reported by CoinDesk on Monday, a source familiar with Kelp’s position said a communications channel between the two teams had been open since July 2024 and that LayerZero had not issued a specific recommendation to change the rsETH DVN configuration. The source said the compromised DVN was LayerZero’s own infrastructure and that Kelp’s core restaking contracts were not affected.

Yearn Finance core developer known on X as @banteg, published a technical review showing LayerZero’s public V2 OApp Quickstart uses a 1-of-1 DVN setup in its reference configuration across Ethereum, BSC, Polygon, Arbitrum, and Optimism. CoinDesk reported approximately 40% of applications on LayerZero currently run 1-of-1 configurations.

Advertisement

LayerZero has said it will no longer sign messages for any application using a 1-of-1 DVN configuration.

“DeFi has spent years auditing smart contracts. Kelp is the moment the industry realises the threat doesn’t end at the code. Most protocols are completely exposed at the infrastructure layer,” said Yair Cleper, Co-Founder and CEO of MagmaDevs and contributor to Lava Network, a decentralized marketplace for blockchain data providers.

Source link

Advertisement
Continue Reading

Crypto World

Bitcoin Preserves Green Weekly Candle as Markets React to US-Iran War

Published

on

Bitcoin Preserves Green Weekly Candle as Markets React to US-Iran War

Bitcoin (BTC) begins the last full week of April juggling fresh US-Iran war fears as resistance hurdles line up.

Key points:

  • Bitcoin stays green on weekly time frames with multiple nearby price levels in focus.

  • Elliott Wave analysis concludes that $81,000 is Bitcoin bulls’ next “final boss.”

  • A resurgent US-Iran war threatens to unravel last week’s crypto and risk-asset gains.

  • Bitcoin ETFs see major inflows, but investors’ cost basis is still above $80,000.

  • Bitcoin’s true market mean metric reveals that the current bear market remains “mild.”

BTC price can still make “new highs” this week

Bitcoin still managed a “green” weekly candle despite last-minute sellers driving price below $74,000.

Data from TradingView shows a modest recovery ensuing as the new week begins — despite the lingering threat of geopolitical escalation between the US, Israel and Iran.

Advertisement
BTC/USD one-hour chart. Source: Cointelegraph/TradingView

Price now has multiple resistance levels overhead, with the nearest being its 21-week exponential moving average (EMA) at $78,400.

Over the weekend, trader and analyst Rekt Capital stressed the influence of that trend line.

“Bitcoin is rejecting from the 21-week EMA (green),” he noted in an X post alongside a print of the weekly chart. 

“It is this rejection that could force a post-breakout retest of the top of the Double Bottom (~$73k) next week, provided Bitcoin Weekly Closes just like this.”

BTC/USD one-week chart. Source: Rekt Capital/X

In a subsequent post, Rekt Capital said that a successful retest of the $73,000 area would “confirm the breakout” for the bulls.

Continuing, trader CrypNuevo forecast that BTC/USD would continue to trade in a range with an $80,000 ceiling “for the next month.” They acknowledged that it was “unknown” how high the pair could go should the US-Iran war definitively end.

BTC/USDT one-day chart. Source: CrypNuevo/X

Crypto trader Michaël van de Poppe, meanwhile, remained upbeat, seeing a push beyond last week’s local highs next. He noted that there was a new “gap” open above price in CME Group’s Bitcoin futures market.

“Relatively strong bounce upwards on $BTC on Monday, as markets tend to go risk-off prior to the open. Gold has gone down, so no attached risk,” he told X followers on Monday. 

“Bitcoin bouncing upwards, and given that there’s still a gap to $77.3K, I would assume we’re going to see new highs this week.”

BTC/USDT 12-hour chart. Source: Michaël van de Poppe/X

$81,000 emerges as Bitcoin’s “final boss”

In its latest BTC price analysis, crypto market intelligence platform Decode placed specific emphasis on $81,000 as the resistance level to beat.

As part of Elliott Wave analysis, Decode showed BTC/USD trading between the 200-week and 21-week EMAs.

Advertisement

“Bitcoin still pinned below the 21 week ema, but looking pretty good overall, and with the final boss at 81k,” it commented.

This “final boss,” Decode explained in subsequent debate on X, “narrows the options from an Elliott Wave perspective, removing short term bearish counts.”

BTC/USD one-week chart. Source: Decode/X

$81,000 also represents the average entry price for institutional buyers of the US spot Bitcoin exchange-traded funds (ETFs). 

Nearby, the cost basis for Bitcoin’s short-term holders (STHs) — entities hodling for up to six months without selling — is now at $83,500, per data from onchain analytics platform CryptoQuant.

Bitcoin STH cost basis data. Source: CryptoQuant

CryptoQuant notes that the STH spent output profit ratio (SOPR) metric — the ratio of STH coins moving onchain in profit or loss — is circling breakeven.

“If SOPR manages to sustainably move back above 1, it would indicate that STHs are once again realizing profits, which is generally positive for the market as long as values do not become excessive,” contributor Darkfost wrote in a QuickTake blog post last week.

Advertisement

Iran war comeback risks risk-asset “unwind”

The US will release little by way of macroeconomic data in the coming week, but markets have bigger concerns.

With the sudden comeback of the US-Iran war, traders are suddenly revisiting the prospect of higher oil prices and a longer-term knock-in effect on inflation. 

“The sudden change in events has characterized the Middle East conflict since it started at the end of February,” trading resource Mosaic Asset Company commented in the latest edition of its regular newsletter, The Market Mosaic

“And it appears that intensifying hostilities could unwind the bullish action over the past few weeks.”

WTI crude oil fell to its lowest levels since early March last week as markets increasingly bet on the ceasefire and agreements between the US and Iran holding. The fresh breakdown in diplomacy sparked a rebound toward $90 per barrel.

Advertisement

S&P 500 futures avoided a major correction at the weekly open, trading down around 0.6% on Monday.

S&P 500 futures one-day chart. Source: Cointelegraph/TradingView

Continuing, however, Mosaic warned that the writing was already on the wall for the equities rally after the S&P hit fresh all-time highs.

“Simply following breadth, sentiment, and positioning by institutional investors helped flag the recent rally. At the same time, warning signs were already emerging as the S&P 500 broke out to record highs,” it wrote. 

“The number of stocks breaking out to new highs is failing [to] confirm the move in the indexes, while buying pressure from a key group of institutional investors has largely run its course.”

S&P 500 relative highs. Source: Mosaic Asset Company

As Cointelegraph reported, oil prices in particular are under the microscope as a US inflation catalyst. The next print of the Consumer Price Index (CPI), which will reflect the ongoing impact of the war during April, is due for release on May 12.

Risk-on institutions wake up to Bitcoin

The upshot in risk appetite amid Iran relief had a near-instant impact on Bitcoin institutional investment vehicles.

Advertisement

In particular, the US spot ETFs saw considerable capital inflows through Friday, with more than 25,000 BTC entering over five days.

“The latest accumulations by spot ETF firms are significant, as the last time they posted a figure this close was in April 2025, when they added 23,900 units,” CryptoQuant noted in a QuickTake blog post on the topic.

US spot Bitcoin ETF netflows (screenshot). Source: Farside Investors

Data from UK-based investment company Farside Investors confirms that on Friday alone, the net inflows to the ETFs were more than $660 million — the largest single-day total since January.

“Aside from the current milestone, BTC spot ETFs are recovering,” CryptoQuant continued. 

“The balance held by the firm offering them has been declining since October, but has risen since the February dip.”

US spot Bitcoin ETF holdings data. Source: CryptoQuant

In BTC terms, the ETFs’ total holdings are now at their highest since November 2025.

Commenting on X, Andre Dragosch, European head of research at crypto asset manager Bitwise, acknowledged that ETF investors’ cost basis is still above spot price at $81,000, increasing the psychological significance of that level as a resistance hurdle.

Bitcoin price downside still on “milder path”

The average Bitcoin hodler remains underwater despite the recent trip to 10-week highs for BTC/USD.

Related: Bitcoin can grow ‘probably a lot bigger’ than $30T+ gold market — Analysis

New research from onchain analytics platform Glassnode also warns that in terms of history, Bitcoin’s current bear-market drawdown remains “mild.”

Advertisement

In an X article published on Thursday, lead analyst CryptoVizArt used the true market mean (TMM) metric to assess hodler profitability. TMM filters out long-dormant or lost coins to provide a more accurate picture of cost basis for the active BTC supply.

“When BTC trades below TMM, the average active holder is underwater. Since 2016, this has happened ten times with meaningful negative outcomes — episodes lasting from 2 days to over 11 months, with max drawdowns ranging from -0.1%  to -57%,” they summarized.

Bitcoin true market mean chart. Source: Glassnode

Bitcoin is now over 75 days into its latest sub-TMM phase, with TMM itself at $78,200.

A chart plotting 2026 against Bitcoin’s historical average dips below TMM shows price forging a “milder path” than before.

“That said, 75 days is still early. The 2018 and 2022 episodes didn’t bottom until months 5-9,” CryptoVizArt warned. 

Advertisement

“The signal isn’t ‘all clear’ — it’s ‘watch closely.’ Reclaiming the TMM and stabilizing there would mark active investors returning to profit, historically a strong reset point for momentum.” 

BTC price performance comparison. Source: CryptoVizArt/X