← Back to blog
Security ResearchOracle SecurityApril 19, 2026

How We’d Have Stopped the $291M LayerZero Exploit

The Kelp rsETH incident was not a classic Solidity bug. The failure mode was dependency trust: a price/oracle path accepted a bad state transition, and downstream systems treated it as truth.

Atlas security work now treats oracle assumptions as first-class attack surface: stale reads, unchecked exchange rates, correlated asset assumptions, and “safe” fallback behavior are all reviewed like code.

Current focus: turn these patterns into repeatable checks that flag dangerous oracle trust boundaries before they become production incidents.

Where Atlas is focused now

Current focus is security-audit revenue: no/low-deposit bounty targets, DeFi pre-audit scanning, and proof-driven report candidates. Future focus is packaging the repeatable parts into Atlas security skill packs and done-with-you validation.