Back to feed
Dev.to
Dev.to
7/13/2026
The $292M KelpDAO Bridge Hack: Why the Audit Wasn't the Problem

The $292M KelpDAO Bridge Hack: Why the Audit Wasn't the Problem

Short summary

A $292M KelpDAO bridge hack and a $285M Drift Protocol loss in 2026 were both caused by social engineering of key holders, not code bugs. Audits remain necessary but only cover code-level vulnerabilities, not operational security failures like phishing, weak multisigs, or missing circuit breakers. AI helps with code analysis but also lowers the bar for attackers scanning for exploits, so teams must use it defensively on their own attack surface first.

  • KelpDAO and Drift hacks were social engineering attacks on key holders, not code bugs
  • Audits are scoped to code vulnerabilities and cannot address operational security gaps
  • AI assists contract analysis but also enables automated exploit reconnaissance

Generated with AI, which can make mistakes.

Is this a good recommendation for you?

Comments

Failed to load comments. Please try again.

Explore more