Ripple CTO Says RLUSD Evaluation Revealed Same Vulnerability That Drained $292M From Kelp DAO

Ripple CTO Says RLUSD Evaluation Revealed Same Vulnerability That Drained $292M From Kelp DAO

N
News Editor 01
2026-07-22 17:10:14
Ripple CTO David Schwartz revealed that during RLUSD bridge assessments he spotted a recurring pattern: providers pitch top security features but advise against using them—exactly the weakness behind Kelp DAO's $292M exploit.
RippleRLUSDcross-chain bridge securityKelp DAOLayerZero

David Schwartz, Ripple's CTO Emeritus, dropped a pointed observation this week: the conditions that allowed the $292 million Kelp DAO rsETH bridge exploit were already visible when he evaluated bridging systems for RLUSD.

“I evaluated a lot of DeFi bridging systems for use by RLUSD, almost exclusively focused on security and risk,” Schwartz wrote on X. “One thing I noticed: most were very well designed and had strong mechanisms against exactly the type of attack that hit KelpDAO—but something else was off.”

The Sales Pitch: Security as an Upsell You Skip

The pattern Schwartz described is consistent. Bridge providers would pitch their most advanced security features prominently, then immediately suggest those features were optional and most customers didn't bother.

“They generally recommended not using the most important security mechanisms because of convenience and operational complexity costs,” he wrote. “We were frequently pitched the simplicity of adding more chains, with the implicit assumption we wouldn't use their best security features.”

“Their sales pitch was: we have the best security, they're easy to use and scale—assuming you don't use the security features,” Schwartz said.

What Actually Happened to Kelp DAO

On April 19, Kelp DAO detected suspicious cross-chain activity and paused contracts across mainnet and L2 networks. Approximately 116,500 rsETH—worth around $292 million at the time—was drained via LayerZero-related contract calls.

On-chain analysis by D2 Finance traced the root cause to a private key leak on the source chain, creating a trust issue with OApp nodes that the attacker exploited to manipulate the bridge.

Schwartz offered his own hypothesis: “I have a funny feeling part of the problem is going to be something like KelpDAO choosing not to use key LayerZero security features out of convenience.”

LayerZero itself offers robust mechanisms, including decentralized verification networks. Investigators are now examining whether Kelp DAO configured a minimal security setup—specifically, a single point of failure with LayerZero Labs as the sole verifier—rather than the more secure alternatives available.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
100

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.