RPC Infrastructure Compromise
Treat this as a reported explanation to test against code, traces, transaction data, and other primary evidence.
Checking the session, access policy, and current workspace data.
RPC Infrastructure Compromise
Compromised DVN oracle led to $292M RSeth drain via cross-chain message forgery.
Imported-record overview
These fields reproduce or normalize claims in an imported research record. “Reported” describes provenance; it does not mean ChainRadar has confirmed the claim.
Treat this as a reported explanation to test against code, traces, transaction data, and other primary evidence.
Date-free learning path
Synthetic study sequence for learning purposes; timestamps and ordering may not reproduce the full verified incident chronology. Synthetic dates are deliberately omitted below.
STUDY PHASE
rpc_hijack()validator_compromise()STUDY PHASE
forgeDepositProof()signMessage()STUDY PHASE
DVN.validateMessage()Endpoint.receivePayload()STUDY PHASE
KelpDAO.mintRSeth()Bridge.deposit()STUDY PHASE
UniswapV3.swap()Curve.exchange()Balancer.exitPool()STUDY PHASE
LayerZero.send()TornadoCash.withdraw()Teaching model
Educational reconstruction intended to explain the reported attack pattern, not a transaction-level evidentiary trace.
Start at Stage 1 and follow the numbered arrows. Every label is derived from the imported flow actions and structure.
Values describe reported movement between stages. Repeated amounts are not additional losses.
| Step | From | To | Reported action | Value |
|---|---|---|---|---|
| 01 | Reported fake input | Kelp DAO system | Fake Deposit | $292M |
| 02 | Kelp DAO system | rsETH minted | Mint rsETH | $292M |
| 03 | rsETH minted | Uniswap swap route | Uniswap Swap | $150M |
| 04 | rsETH minted | Curve swap route | Curve Swap | $142M |
| 05 | Uniswap swap route | Proceeds destination | ETH Profit | $150M |
| 06 | Curve swap route | Proceeds destination | Stablecoin Profit | $142M |
Imported indicators
Contract entries are reproduced from the local research archive. Confirm chain, bytecode, ownership, and incident relevance against primary evidence before using them in an investigation.
0x85d456B2DfF1fd8245387C0BfB64Dfb700e98Ef30x1a44076050125825900e736c501f859c50fE728c0x8B1b6c9A6DB1304000412dd21Ae6A70a82d60D3bDefensive prompts
These imported mitigation labels are study prompts, not a complete or validated remediation plan. Test them against the protocol's actual architecture and failure mode.
Investigator workflow
Turn this background study into questions for a separate, evidence-led investigation. Never promote an educational edge or imported label into a finding without corroboration.
Preserve official disclosures, on-chain transactions, code, retrieval times, and other evidence supporting each material claim.
Start from corroborated addresses or transactions and trace each hop without assuming the educational flow is exact.
Compare decoded calls, logs, bytecode, and state changes with the reported cause.
Record provenance for every claim and identify gaps that still require confirmation.
Source status: cataloged. Classification: educational. Risk methodology: heuristic only. Primary-source verification remains required for every material claim.