This week the
@arbitrumdao_gov Security Council froze 30,766 ETH (~$71M) connected to the
@KelpDAO exploit, taking it out of reach of the Lazarus Group (a hacking collective with ties to the DPRK).
Certora's VP of Security Labs Elad Erdheim was one of the signers protecting the funds.
Before it all happened, our team flagged two critical edge cases that hadn't been identified yet:
1. If the recovery process wasn't atomic, it would open a window for anyone to drain
@arbitrum user funds. Billions of dollars would have been exposed.
2. If the exploiter reduced their balance by even a small amount, the proposed tx would fail, giving them time to move funds before the council could regroup and sign a new one.
Both issues were mitigated before the transaction was finalized: the sequencer could be paused in either scenario, giving the council a 24-hour window to respond.
The tx went through. $71M was protected thanks to smart, thoughtful, and security-first responders.
Certora supports decentralization. And we support the failsafes, circuit breakers, and redundancies that will help the industry mature.