@GTO_Diaper@WSOP the problem is that you don't know which card should have been the burn. The dealers puts down 3 cards, so 3 motions off the top of the deck, which one of those contained the double feed? We have no idea, and clearly the dealer doesn't either.
- signed, a dealer
You are ignoring the elephant in the room
LayerZero Labs’ centralized infrastructure was infiltrated by North Korea, which resulted in a $292 million bridge exploit
How did this massive security failure, which occurred on your infrastructure, take place exactly?
Rather than throwing Kelp under the bus, again, maybe you can address some of these points:
1. How exactly did North Korea (DPRK) gain access to your core node & RPC servers on your supposedly hardened infrastructure? What was their initial access?
2. How did your endpoint detection (EDR) and cloud monitoring not detect this intrusion? Were these not running in these critical systems?
3. How long did the DPRK have persistence on the LayerZero infrastructure without being detected?
4. What other systems, data, code, and internal sensitive customer information did they access? If they were on your cloud infra, it stands to reason they also had access to your internal tools (GDrive, Email, Slack, etc).
5. Will you or LayerZero Labs take responsibility for these security failures or has your legal counsel advised you not to comment to avoid accepting liability?
After the recent LayerZero exploit, we are taking steps to ensure rsETH is fully secure, which is why we are migrating to @chainlink CCIP.
From the April 18 incident, it is clear that LayerZero's own infrastructure was exploited, resulting in $300M in losses across DeFi. Independent reports from SEAL 911, Chainalysis, and other major leading security researchers all point to the same origin.
There are questions that the ecosystem deserves answers to. And we are ensuring rsETH is secured by infrastructure that doesn't leave these questions open.
That’s why we’re setting the record straight.
Narrator:
Most of the LayerZero configs were 1/1.
It should not come as a "surprise" for the LayerZero foundation CEO. Multiple security researchers have warned about this for years. LayerZero did not just ignore warnings; it actively shot the messengers.
Here: https://t.co/N1AX5BKTTF
Here: https://t.co/T8m5pgbNnI
Here: https://t.co/f57huSEXq6
Here: https://t.co/c2F8ANfDgA
etc.
In LayerZero, the zero stands for zero spine and 100% bullshit.
Rather than provide additional info on how and why LayerZero Labs' centralized infrastructure was infiltrated by North Korean (DPRK) hackers, which resulted in the $292M rsETH bridge exploit
Bryan decides throwing the user under the bus the first time wasn't good enough, they just had to do it again for good measure!
All for the crime of trusting the LayerZero Labs team and their infra, using a 1/1 config that ~50% of LZ OApps use (per @Dune), that the LZ Labs DVN supported (until it was blocked), and that the LZ Labs team monetized (DVN fees)
Why take responsibility, and therefore legal liability, over the exploit when finger pointing is just as good
👆👉👇👈
And nevermind the fact that there are multiple chains in the LZ docs where the LZ Labs DVN is the only one listed, and therefore the only possible config !
Why did the LZ Labs DVN support a 1/1 config up until now if it was such an obviously dangerous thing? Why isn't this config blocked at the protocol level if its always been so obviously bad?
People have been pointing out the massive centralization problem in the LayerZero ecosystem for YEARS now, including the 2/2 multisig Stargate bridge run by the LZ Labs team (does anyone genuinely think a 2/2 multisig bridge setup is really all that much better than 1/1?)
But only after the $292M bridge hack is such centralization now such an obvious risk, give me a break
Why should anyone integrate LayerZero, knowing they're going to be thrown under the bus as disposable meat the moment the LZ Labs fucks up and gets hacked by North Korea?
>get seeded from SBF and Alameda
>run infra from moms basement
>play poker with every industry player insisting infra is decentralized
>fast forward 4 years, LZ underpins a good segment of crypto
>North Korea exploits LZ infra and $300M is poofed away
>gaslight and ask for pity
Seems like @SiloFinance is failing its community airdrop allocations still unpaid, oracle issues surfacing repeatedly, and instead of transparency, anyone asking questions gets removed from Discord.
Where is the accountability here?
@SonicLabs openly having a partnership with these guys.
@michaelfkong@AndreCronjeTech - will you address these concerns, or remain silent while this continues?
Lack of communication and accountability only erodes trust further.
Does trust even remain ?
Or hey just throw out some metrics and the "people" will be happy
#DeFi #Crypto #Airdrop #Transparency #Web3 #CryptoCommunity #DeFiAccountability #Blockchain #Trust #DoBetter
Dear @SiloFinance,
Will we ever receive the airdrop we earned, or was the plan just to ban us from Discord and ignore your own commitments? 🤔
We staked over 500,000 S with your platform in good faith and in return, we’ve received nothing.
No transparency, no communication, just silence. 🚫
This isn’t how you treat your community.
Do better. ⚠️
Guess the reasons why @SonicLabs is partnering with them because the thought process aligns .
#Crypto #DeFi #Airdrop #Transparency #Web3 #CryptoCommunity
Did you really just accidentally say that Thorchain was centralized for all of those years while DPRK laundered hundred of millions while raking in millions of fees with an admin key you held in your possession?.
Cannot wait until your post shows up in an court indictment one day.
To be clear: North Korean hackers infiltrated LayerZero Labs’ centralized infrastructure and stole $290M
Rather than explain how that happened, LZ put out a statement carefully worded by lawyers to minimize their liability and threw KelpDAO under the bus for trusting them