Charles Hoskinson Points to Cardano and Midnight as Fix for Cross-Chain Flaws Behind KelpDAO Hack

Charles Hoskinson Points to Cardano and Midnight as Fix for Cross-Chain Flaws Behind KelpDAO Hack

N
News Editor 01
2026-07-08 16:14:13
A cross-chain message forgery attack drained 116,500 restaked ETH ($292M) from KelpDAO on April 18, triggering over $13B in TVL outflows. Charles Hoskinson says Cardano's liquid staking and Midnight's zero-knowledge proofs can prevent such attacks.
KelpDAOCharles HoskinsonCardanoMidnightcross-chain security

On April 18, 2026, KelpDAO suffered a sophisticated cross-chain message forgery attack that drained 116,500 restaked ETH worth approximately $292 million. The attacker forged a Layerzero message to a one-of-one decentralized verifier network (DVN), releasing tokens from an Ethereum escrow. This stands as the largest DeFi exploit of the year so far.

The stolen assets were quickly deposited as collateral in lending markets like Aave, triggering a contagion that saw over $13 billion in total value locked (TVL) exit the broader DeFi ecosystem within 48 hours. At least nine protocols were directly affected, including Compound, Morpho, Lido, Ethena, Pendle, Euler, Beefy, and Lombard Finance. Aave alone experienced outflows between $6.6 billion and $8.45 billion.

Hoskinson: Bridge Verification Failures Are the New Primary Threat

Cardano founder Charles Hoskinson released a video analysis from Wyoming, highlighting the root cause: KelpDAO relied on a single decentralized verifier network, a one-of-one setup that left a single point of compromise. “The standard DeFi threat model assumes smart contract bugs are the dominant risk. That’s not true anymore,” Hoskinson said. He emphasized that the forged message claimed Uni-Chain endpoint ID 30320 as its source, and the one-of-one configuration was the critical flaw.

The attack exploited a procedural gap: the stolen tokens were not sold directly on DEXs but used as collateral in lending markets before Kelp could freeze positions, allowing the attacker to borrow liquid wrapped ether and exit with clean assets. Hoskinson noted, “Bridges can be very problematic. A one-of-one verifier is not good. Don’t do that.”

How Cardano and Midnight Address the Vulnerability

Hoskinson argued that Cardano’s liquid, non-custodial staking design eliminates the staking-to-liquid-staking-to-restaking wrapper chain that created the attack surface at Kelp. “If you’re in Cardano land, you just click delegate… We’re liquid non-custodial,” he said.

He pointed to Midnight, Cardano’s privacy-focused sidechain, as the concrete fix. Its Nightstream protocol folds entire chain states into zero-knowledge proofs that travel alongside cross-chain messages, enabling verification before acceptance. “When people send messages, they can verify that what they’re seeing is correct,” Hoskinson explained. Additionally, Midnight supports multi-party computation (MPC), allowing Layerzero to deploy turnkey two-of-three or five-of-seven DVN configurations with minimal friction, thereby eliminating the single point of failure.

AI and the Escalating Threat Landscape

Hoskinson also warned that AI tools, including frontier models reportedly accessible to the Lazarus Group through bribed insiders at major AI labs, are enabling attackers to scan entire codebases for emergent vulnerabilities. “Hacks are a part of life, and they’re going to get much, much worse for everyone,” he said.

Three separate post-mortems have been published by KelpDAO, Layerzero, and Llamarisk, none agreeing on responsibility. Layerzero announced it would no longer sign or attest messages for any application running a one-of-one DVN configuration, pushing a protocol-wide migration to multi-verifier setups. The incident underscores that cross-chain security remains the Achilles’ heel of DeFi, and Cardano’s design philosophy offers a viable alternative.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
200

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.