Connect with us
DAPA Banner

Tech

KelpDAO suffers $290 million heist tied to Lazarus hackers

Published

on

KelpDAO suffers $290 million heist tied to Lazarus hackers

State-sponsored North Korean hackers are likely behind the $290 million crypto-heist that impacted the KelpDAO DeFi project on Saturday.

The attack reportedly also impacted the lending protocols Compound, Euler, and Aave, with the latter announcing a freeze and blocking new deposits or borrowing using rsETH as collateral.

KelpDAO is a decentralized finance (DeFi) project built around liquid restaking on the Ethereum network. It accepts user ETH deposits, restakes them, and returns a liquid token named ‘rsETH,’ that represents the restaked position.

image

The rsETH token is meant to help users keep earning restaking yield, while it stays usable across DeFi, including cross-chain via LayerZero, an inter-blockchain communication protocol and interoperability layer.

On April 18, KelpDAO announced that it detected “suspicious cross-chain activity” involving rsETH, forcing it to pause rsETH contracts across the Ethereum mainnet and L2s.

Advertisement

The project launched an investigation with the help of LayerZero, Unichain, and other partners.

Tweete

Blockchain activity showed that around 116,500 rsETH were stolen, around $293 million in USD value, and went through Tornado Cash to hide the trace.

According to additional details that LayerZero shared today, the attack targeted the verification layer (DVN) used to validate cross-chain messages for rsETH.

Specifically, the attackers compromised some RPC nodes used by the verifier, feeding it falsified blockchain data, while simultaneously DDoS-ing healthy RPC nodes to force the system to rely on the “poisoned” ones.

Advertisement

This allowed a fake cross-chain message to be accepted as valid. The system confirmed transactions that never actually occurred on-chain and enabled moving the rsETH without authorization.

Based on preliminary evaluation of the attack indicators, LayerZero believes that the infamous Lazarus hackers are likely responsible for the heist.

“Preliminary indicators suggest attribution to a highly sophisticated state actor, likely DPRK’s Lazarus Group, more specifically TraderTraitor,” stated LayerZero.

The protocol also noted that the incident was isolated to rsETH and that there’s no broader contagion across other apps or assets.

Advertisement

While the KelpDAO breach constitutes a major loss so far this year in terms of the stolen amount, the Lazarus Group has also been linked to another large theft, $280 million from the Drift Protocol.

According to a post-mortem report, that attack was the result of a six-month-long, carefully planned operation that involved malicious agents attending conferences and $1 million deposits into the project.


article image

AI chained four zero-days into one exploit that bypassed both renderer and OS sandboxes. A wave of new exploits is coming.

At the Autonomous Validation Summit (May 12 & 14), see how autonomous, context-rich validation finds what’s exploitable, proves controls hold, and closes the remediation loop.

Claim Your Spot

Source link

Advertisement
Continue Reading
Click to comment

You must be logged in to post a comment Login

Leave a Reply

Tech

Nvidia research promises 2x to 3x faster path tracing with better visuals

Published

on


A new research paper from Nvidia describes how an in-development update to ReSTIR (Reservoir Spatiotemporal Importance Resampling) path tracing addresses several of its flaws. While the technology is not quite ready for implementation in commercial games, it could enhance path tracing performance by 100% to 200%.
Read Entire Article
Source link

Continue Reading

Tech

Yelp’s AI chatbot can now make your dinner reservation

Published

on

Every business seems to think that its customers want more AI. Yelp is the latest to add more artificial intelligence tools. The review site has upgraded its Yelp Assistant, an agentic AI chatbot, to work across all of Yelp’s categories. Yelp Assistant was initially launched in 2024 with a limited scope and then expanded in 2025.

With the latest update to its chatbot, Yelp Assistant can handle natural language queries for finding a specific local business. It can also be used to take some additional actions, such as making a restaurant reservation or ordering takeout. Yelp’s spring product updates introduced new third-party integrations with Vagaro, ZocDoc and Calendly. Yelp Assistant can also use these integrated services for booking appointments in related fields. The chatbot now has a dedicated Assistant tab in the iOS and Android apps, and it can also be accessed directly from business pages for certain fields, such as restaurants and retail shops. Support for all business types and a desktop version are planned for later in 2026.

Other AI features coming to Yelp include a personalized home page on mobile and extra photo discovery tools.

Source link

Advertisement
Continue Reading

Tech

Former ransomware negotiator pleads guilty to BlackCat attacks

Published

on

BlackCat

41-year-old Angelo Martino, a former employee of cybersecurity incident response company DigitalMint, has pleaded guilty to targeting U.S. companies in BlackCat (ALPHV) ransomware attacks in 2023.

Together with two other Sygnia and DigitalMint ransomware negotiators (33-year-old Ryan Clifford Goldberg and 28-year-old Kevin Tyler Martin), Martino was charged with conspiracy to interfere with interstate commerce by extortion, interference with interstate commerce by extortion, and intentional damage to protected computers.

Martino was initially identified only as “Co-Conspirator 1” in an October 2025 indictment, but was named in court documents unsealed in March. Martin and Goldberg also pleaded guilty to conspiracy to obstruct commerce by extortion and are facing up to 20 years in prison each.

image

According to court documents, while working as a negotiator for five victims, Martino shared confidential information about the victims’ negotiation positions and insurance policy limits with BlackCat ransomware operators, helping the cybercriminals extort the maximum possible amount.

Between April 2023 and April 2025, he was also involved in BlackCat ransomware attacks alongside accomplices Kevin Tyler Martin and Ryan Goldberg.

Advertisement

While operating as BlackCat affiliates, the three defendants demanded ransom payments and threatened victims to leak data stolen before encrypting their systems. Prosecutors added that the three accomplices paid the BlackCat administrators a 20% share of all ransoms proceeds for access to the ransomware and extortion portal.

Their victims included at least five U.S. organizations, among them a financial services firm that paid $25,660,000 and a nonprofit that paid a $26,793,000 ransom, as well as law firms, school districts, medical facilities, and other financial services companies.

DigitalMint CEO Jonathan Solomon told BleepingComputer that the company condemned the previous malicious conduct and noted that Martin and Martino were fired after their actions were discovered.

“We strongly condemn these former employees’ criminal behavior, which violated our values, ethical standards, and the law. When we learned about the conduct, we immediately terminated both individuals,” Solomon said.

Advertisement

The BlackCat ransomware operation has been linked by the FBI to more than 60 breaches between November 2021 and March 2022. In a separate advisory, the bureau added that the cybercrime gang collected at least $300 million in ransom payments from over 1,000 victims through September 2023.


article image

AI chained four zero-days into one exploit that bypassed both renderer and OS sandboxes. A wave of new exploits is coming.

At the Autonomous Validation Summit (May 12 & 14), see how autonomous, context-rich validation finds what’s exploitable, proves controls hold, and closes the remediation loop.

Claim Your Spot

Source link

Advertisement
Continue Reading

Tech

Crafting a 2,500-LED Matrix That Fills an Entire Wall

Published

on

DIY Homemade 2,500 LED Matrix Wall
Rooms come alive as thousands of LEDs illuminate in perfect time over a large 50×50 panel. Chris Maher took on this task by converting regular light strips into that massive display without breaking the bank or requiring several controllers. His finished presentation plays well on a single 12-volt power supply and some pretty tiny gear, offering professional-looking animations, text, and patterns.



Chris purchased 18 5-meter rolls of 12-volt SK6812 strips, each with 30 LEDs per metre, so obtaining the necessary components was simple. He then sliced each roll into three 50 LED portions, for a total of 54 segments, plus a few spares for safety. To provide support, he built a simple wooden frame out of one-by-two boards and some board-and-batten panels. The rest of the kit consisted of a few short sections of 18-gauge silicone wire, lever-style connections, rubber grommets, and a Gledopto 4D-EXMU controller loaded with WLED firmware, as well as a standard 12-volt power supply.

Sale


Govee Curtain Lights Pro, Upgraded 960 LEDs Smart Color Changing LED Curtain Lights with AIGC, Dynamic…
  • Smoother, Silkier Animations: Featuring 960 ultra-dense RGBIC LEDs and a next-gen 20x-speed chip, the smart curtain lights support high-capacity…
  • Higher Creative Freedom: Unleash creativity with the led smart curtain lights, offering a 30-layer canvas for uploads, 1,000+ assets. Craft stunning…
  • Year-Round Lighting: The curtain fairy lights bring any occasion to life with 250+ preset modes, tailored for holidays, parties, and daily ambience…

DIY Homemade 2,500 LED Matrix Wall
First, he had to get the strips ready to go, so he carefully removed the connections from the ends, soldered the exposed pads, stripped, tinned, and prepared all of the wires for connection. This preliminary work made the final assembly a lot simpler. Next came the frame, which he built by stacking and screwing the boards together to form a solid rectangle the same size as the finished grid. He added some board-and-batten panels to the front to provide a firm surface to screw the strips to. He painstakingly wrote out the places of each strip, ensuring that they were perfectly spaced from edge to edge. He then placed the strips down in a zig-zag pattern, alternating direction row by row, to form a single long continuous data channel.

DIY Homemade 2,500 LED Matrix Wall
Holes were drilled above and below each strip, and rubber grommets were inserted to allow the wires to pass through to the back side while keeping the front of the display neat and free of connections. At several spots, lever-style connectors were utilized to connect the power and data lines, and separating the grid into four distinct data runs ensured that everything remained in sync.

DIY Homemade 2,500 LED Matrix Wall
The wiring was rather simple, as you just connect the voltage, ground, and data wires in that order. He utilized colored wire markers to keep track of which was which during assembly. The controller and power supply were fastened to the back with simple clips and wooden blocks. A French cleat system on the back makes it simple to mount the complete panel to a wall. Once he had everything configured inside the WLED interface, it was only a matter of selecting the SK6812 type, validating the 12-volt system, and specifying the 50×50 pattern with a vertical zig-zag orientation. Some brightness limitations were set to protect the power supply, and four data outputs were allocated to each block of LEDs. Once everything was saved, the display would respond promptly to requests for colors, effects, or scrolling messages.
[Source]

Advertisement

Source link

Continue Reading

Tech

The Internet Archive makes 758 classic PC Gamer demo discs available to the public

Published

on


Getting to try snippets of new games without having to spend extra money at your local rental store was awesome, and it was doubly cool for PC games, since rental outlets for such titles weren’t a thing. Some of my earliest PC gaming memories involved demo discs, and now thanks…
Read Entire Article
Source link

Continue Reading

Tech

Homeland Security reportedly wants to develop smart glasses for ICE

Published

on

The Department of Homeland Security (DHS) is reportedly developing smart glasses that could be used to collect intelligence on immigrants and US citizens, journalist Ken Klippenstein reported. The devices would help ICE agents identify “illegal aliens” from a distance by capturing video and comparing it to biometric data like facial recognition and walking gait, according to budget documents seen by Klippenstein. The DHS wants to deploy the “ICE Glasses” by September 2027.

“The project will deliver innovative hardware, such as operational prototypes of smart glasses, to equip agents with real-time access to information and biometric identification capabilities in the field,” the document states. The glasses could allow agents to compare observed subjects against existing biometric databases and identify them in real time during interactions.

Such devices could help make surveillance of US residents “ubiquitous,” according to the report. “It might be portrayed as seeking to identify illegal aliens on the streets, but the reality is that a push in this direction affects all Americans, particularly protestors,” a DHS lawyer speaking on the condition of anonymity told Klippenstein.

The deployment of such devices is worrying to civil liberty groups, particularly in light of recent law enforcement activities under the Trump administration. The FBI was reportedly directed by the Department of Justice to “compile a list of groups or entities” who demonstrate “anti-Americanism,” according to a previous Klippenstein investigation.

Advertisement

It’s not the first time smart glasses have come up in reports about the DHS. An investigation by The Independent last month found that ICE and Border Patrol agents in six states were using Meta’s AI smart glasses of their own accord, in possible violation of DHS rules. Congress has reportedly been notified of the DHS’s Ice Glasses project but has yet to comment publicly.

 

Source link

Advertisement
Continue Reading

Tech

Daily Deal: The Complete Arduino, Raspberry Pi & ESP32 Bundle

Published

on

from the good-deals-on-cool-stuff dept

The Complete Arduino, Raspberry Pi, and ESP32 Bundle has 14 courses covering what you need to get started on building out your own smart home. After learning the basics, courses show you how to create a weather monitoring system, a smart home security system, a plant watering system, and more. Courses also cover getting familiar with Home Assistant, Tasmoto firmware, networking, and electrical systems. It’s on sale for $50.

Note: The Techdirt Deals Store is powered and curated by StackCommerce. A portion of all sales from Techdirt Deals helps support Techdirt. The products featured do not reflect endorsements by our editorial team.

Filed Under: daily deal

Source link

Advertisement
Continue Reading

Tech

Why Some S3 Videocards Have A Brightness Issue

Published

on

Once a pioneer in videocards, S3’s legacy is today mostly found in details like texture compression as well as the strong presence of S3-branded videocards in the retro-computing world. There’s however a bit of a funny issue with some of these S3 cards in what is often called a ‘brightness bug’, but which as [Bits und Bolts] covers in a recent video was actually a hardware feature that we can once again blame composite video for.

This issue appears with AGP cards like the Trio 3D, Trio64 and ViRGE, where the brightness on the output signal is set too high, easily seen with the washed out look on boot, where especially on CRTs you’d expect to see the nice deep black background. Using an S3 Trio 3D 2X card that was saved from the e-waste pile this so-called Pedestal Bit responsible is investigated and tweaked to show what difference it makes.

At the core is adjusting the black level to make scanline changes easier to detect for TVs, which is no longer relevant for CRTs, LCDs, etc., while adjusting the brightness for one videocard in a system can cause issues elsewhere, such as when using said card alongside a 3dfx Voodoo II card or with inconsistent brightness levels inside 3D games.

Advertisement

Fortunately S3 provided in-depth datasheets on their chips, including how to address the responsible bit. After demonstrating the principle, the BIOS is then patched to set this Pedestal Bit to the value of 0 on boot, solving the issue once and for all.

Advertisement

Source link

Continue Reading

Tech

How to Watch the 2026 Lyrids Meteor Shower at Its Peak

Published

on

In mid-April, astronomy enthusiasts will be able to enjoy one of the classic celestial spectacles. The meteor shower known as the Lyrids will illuminate the sky, especially in the northern hemisphere, and anyone will be able to see it with the naked eye, weather permitting—if they know where to look.

The Lyrids began to appear as early as April 14, but their activity peaks between the night of April 21 and the early morning of April 22, according to NASA. During those hours, the shower will show 15 to 20 meteors per hour under dark skies.

The shower gets its name because the meteors appear to emerge from the constellation Lyra. Locating the radiant is simple if you use an astronomical mapping app: Just find Vega, the fifth brightest star in the sky, surpassed only by Sirius, Canopus, Alpha Centauri A, and Arcturus. Once you locate it, look around it; the luminous traces of the Lyrids will seem to be projected from that point due to a perspective effect. Keep in mind that it takes 20 to 30 minutes for the human eye to adjust to darkness.

The moon will be in early crescent phase during the peak, so its light will interfere very little. With a dark sky, meteors should stand out easily. The shower is usually visible from 10 pm to dawn, although early morning offers the best conditions. It is best to stay away from light pollution and, if possible, to observe from high ground. An outing to the mountains works well.

Advertisement

Each meteor shower has a different origin. In April, Earth crosses the cloud of fragments left by comet C/1861 G1 (Thatcher) in its orbit around the sun. This comet, discovered in 1861, takes about 415 years to complete its journey. The grains of ice and rock that it released centuries ago enter the atmosphere at high speed and produce the flashes we know as the Lyrids.

After the Lyrids, the calendar still holds several spectacles for those who follow the night sky. The Eta Aquarids will arrive in May with debris from Halley’s Comet. The Perseids will appear in August, the Orionids will return in October, and the year will close with the Leonids in November and the Geminids in December. The latter is considered the most intense and reliable shower on the calendar.

This story originally appeared on WIRED en Español and has been translated from Spanish.

Source link

Advertisement
Continue Reading

Tech

YouTuber Copyright Struck After Others Layer AI Voiceovers On Video Game Music

Published

on

from the fix-this-youtube dept

It’s barely been a few days back since we discussed just how open to mistakes and abuse YouTube’s copyright takedown system is, when NVIDIA’s demo video for its controversial DLSS 5 tech got briefly pulled down because an Italian news channel did a piece featuring the footage which it copyrighted. The copyright bots took it from there and the actual source material for the news footage got booted.

While that is a great example of an obvious simple error resulting in copyright collateral damage, there have been plenty of examples of abuse resulting in this sort of thing, too. And if you want a great example of how this could all get much, much worse thanks to AI, you need look only at let’s play YouTuber Nubzombie getting two copyright copyright claims on his video of Silent Hill 2 gameplay for most absurd reasons. It seems multiple people have taken music from the game, originally by Akira Yamaoka, and layered some lazy AI-created voiceovers on top of it and then setup automatic copyright enforcement for those sounds.

Earlier last night, content creator Nubzombie uploaded a video titled A.I. IS RUINING YOUTUBE (and my life). In the video, Nubzombie states that their latest playthrough of the original version of Silent Hill 2 was hit with a copyright strike by someone called “Agro memos.” As you can see (or rather hear), in Nubzombie’s video, the track that the Agro memos strike is protecting is a clear copy of Akira Yamaoka’s track “Promise,” but with an AI-generated voice over top.

Then, in the space of a few hours, Nubzombie uploaded a second video. As they explain in that follow-up, as soon as their first video had finished uploading to YouTube, their Silent Hill 2 playthrough was hit with a second copyright strike. This time, it was from a different artist, named “詹姆斯.K,” but the copyright claimer this time isn’t even trying to hide the fact that their track is a ripoff of Akira Yamaoka’s “Promise”…because 詹姆斯.K’s track is literally called “Promise.”

This has always been the problem with YouTube’s automatic and bot-driven copyright enforcement mechanisms. There is very little that gets in the way of bad actors claiming copyright on all kinds of content actually produced by others, sometimes with this sort of languorous and brief additions to said content, and then slap copyright enforcement on it to issue automatic takedowns or demonetization claims. That YouTube has allowed this problem to fester for years and the timeline is now colliding with the prevalence of AI tools that make all of this even easier for the bad actors is inexcusable.

Advertisement

Though it gets a little bit stranger with that first copyright notice, since it appears Sony Music might be involved.

While I couldn’t find any information on the second “Promise” rip-off, I did find something odd regarding the former. Agro memos’ most recent tracks on YouTube, like this one, state in the descriptions that they were “Provided to YouTube by The Orchard Enterprises.”

Orchard Enterprises is a division of Sony Music Entertainment. Turns out Orchard’s got a bit of history of pulling this kind of stunt, dating all the way back to 2022. In this video, content creator EckhartsLadder details how he was repeatedly hit with copyright claims by Orchard Enterprises in 2024 because Orchard falsely claimed that the track  “Resonance” by HOME, which EckhartsLadder used as their intro and outro song for all their videos, belonged to the Sony Music subsidiary.

Sony hasn’t responded to questions about all of this as of the time of this writing, but it damned well should. Best as I can tell, Sony doesn’t have any of the video game rights to the Silent Hill franchise, and this specific game was produced by Konami in 2001, and then a remake was released in 2024. It doesn’t seem to me that Sony should have anything to do with any of this.

But even if some division of Sony is a bad actor in all of this, the onus is on YouTube to fix its platform and protect its creators. This is long overdue.

Advertisement

Filed Under: contentid, copyright, copyright strikes, nubzombie, silent hill 2, takedowns

Companies: sony music, youtube

Source link

Advertisement
Continue Reading

Trending

Copyright © 2025