Owner : @arndxt
Newsletter: https://threadingontheedge.substack.com/
Twitter: https://twitter.com/arndxt_xo
TG: https://t.me/threadingontheedge
Farcaster: https://warpcast.com/arndxt
Lens: https://lenster.xyz/u/arndxt
Post #4466
303
Heeaaaaaaaaated debate broke out in the ETHSecurity Community Telegram earlier today between LayerZero’s Bryan and security researchers.
TLDR summary:
- $3 billion+ of LZ OFTs were recently at risk of being compromised due to a default library contract that LZ Labs could upgrade instantly with no timelock to forge messages (like what happened with rsETH hack)
-According to Banteg, major projects like Ethena and EtherFi were STILL using this default library contract as of a few weeks ago
- There is still $178 million in value exposed to being compromised from projects using default library (look at quote tweet)
- LZ Labs doesn’t need to be malicious for this be risk, they have history of poor opsec (in addition to being hacked by North Korea):
- Onchain data shows LZ Labs multisig signers were engaging in non-multisig signing activity like trading memecoins, swapping on DEX, bridging. All major phishing risks as this mean production multisig keys were connected to websites, not just used for signing
- LZ Labs handled private keys like a high schooler, trading memecoins on production multisig keys, no wonder they got targeted by North Korea, who knows what other poor opsec they have?
THREAD BELOW
https://x.com/catfishfishy/status/2052552571995169044?s=46&t=hr2fbvcHJGpvp_SbDstdzg
X (formerly Twitter) Fishy Catfish (@CatfishFishy) on X Heeaaaaaaaaated debate broke out in the ETHSecurity Community Telegram earlier today between LayerZero’s Bryan and security researchers.
TLDR summary:
- $3 billion+ of LZ OFTs were recently at r… TLDR summary:
- $3 billion+ of LZ OFTs were recently at risk of being compromised due to a default library contract that LZ Labs could upgrade instantly with no timelock to forge messages (like what happened with rsETH hack)
-According to Banteg, major projects like Ethena and EtherFi were STILL using this default library contract as of a few weeks ago
- There is still $178 million in value exposed to being compromised from projects using default library (look at quote tweet)
- LZ Labs doesn’t need to be malicious for this be risk, they have history of poor opsec (in addition to being hacked by North Korea):
- Onchain data shows LZ Labs multisig signers were engaging in non-multisig signing activity like trading memecoins, swapping on DEX, bridging. All major phishing risks as this mean production multisig keys were connected to websites, not just used for signing
- LZ Labs handled private keys like a high schooler, trading memecoins on production multisig keys, no wonder they got targeted by North Korea, who knows what other poor opsec they have?
THREAD BELOW
https://x.com/catfishfishy/status/2052552571995169044?s=46&t=hr2fbvcHJGpvp_SbDstdzg
- ❤ 1