Attacks like KelpDAO/LZ will keep happening until we close the RPC Security gap.
That's why we're partnering with @cyfrin, @hackenclub, @Hashlock_ and @hexens to help teams harden the layers smart contract audits don't reach.
Learn more and check your exposure to RPC attacks 👇
@sidrmsh It was mostly due to bad RPC set up. We see more and more attacks related to RPC infra, and unfortunately that piece of infra is badly maintained again and again.
5 questions every CISO should be asking after the KelpDAO exploit:
1. Do you run your own RPC infra?
2. Do you rely on one primary RPC provider for critical decisions?
3. Do you validate RPC responses across providers, including fallbacks?
4. Do you require multi-source quorum for sensitive operations?
5. Do you use cryptographic proofs to verify on-chain data?
If you're not sure about any of these, the full assessment takes 5 min: https://t.co/ASDHa5XjMA
@valuePods הגרף שאתה מציג משקף רק חלק מהסייקל הארבע שנתי (שנראה שגם הפעם קרה), מה שנראה שכבר לא חלק מהסייקל הארבע שנתי הוא האלט סיזן.
אז אני לא יודע אם להגיד שהוא ״מת״ זה התיאור הנכון אבל הוא בהחלט השתנה.