Skip to content
Blockchain

Why can a single compromised validator approve a $300M bridge withdrawal?

85

機会

Omnichain messaging protocols let bridge deployers choose how many independent verifiers must sign a cross-chain message before funds move. In April 2026, KelpDAO lost $292M because their bridge ran with a single DVN, a configuration that every smart contract audit had cleared because the contract code itself was correct. The exploit did not require finding a code bug; it required compromising one off-chain operator and forging one message. No on-chain enforcement today prevents a bridge from going live with a 1-of-1 setup, and there is no audit standard that covers DVN configuration semantics rather than bytecode logic.

重要な理由

Billions in bridge TVL sit behind audit processes that read code but treat the configuration parameters that actually determine trust minimization as out of scope.

機会をどう評価するか

Opportunity Scoreは測定値ではなく、私自身の見解です。どれほど痛みを伴うか、どれほど頻繁に影響を与えるか、そして今日時点で解決策がいかに少ないか。スコアが高いほど、構築する価値が高いと私は考えています。

深刻度9/10

それが現れたときにどれほどの痛みをもたらすか。

頻度7/10

実際にどれほど頻繁に人々がそれに直面するか。

ホワイトスペース8/10

今日時点で、それに対する優れたツールがいかに少ないか。

解決する価値のある問題をもっと見る