Skip to content
Blockchain

Why can a single compromised validator approve a $300M bridge withdrawal?

85

机会

Omnichain messaging protocols let bridge deployers choose how many independent verifiers must sign a cross-chain message before funds move. In April 2026, KelpDAO lost $292M because their bridge ran with a single DVN, a configuration that every smart contract audit had cleared because the contract code itself was correct. The exploit did not require finding a code bug; it required compromising one off-chain operator and forging one message. No on-chain enforcement today prevents a bridge from going live with a 1-of-1 setup, and there is no audit standard that covers DVN configuration semantics rather than bytecode logic.

为什么重要

Billions in bridge TVL sit behind audit processes that read code but treat the configuration parameters that actually determine trust minimization as out of scope.

我如何评估机会

机会评分是我的个人判断,而非量化指标:痛苦程度、发生频率,以及当前解决方案的匮乏程度。分数越高,意味着我认为越值得去构建。

严重性9/10

出现时造成的痛苦程度。

频率7/10

人们实际遇到它的频率。

空白空间8/10

当前针对它的优质工具有多匮乏。

更多值得解决的问题