Home Blog Page 456

Fair on Closing Coverage Gaps

0

At InsurTech NY, Clinton Houck from Fair explains how the company is addressing a common misunderstanding in auto insurance.

Houck says many consumers assume their auto insurance covers all types of vehicle issues. In reality, standard policies typically focus on accident-related damage, such as collision or comprehensive cover. Mechanical breakdowns, such as engine failure or faulty components, are often excluded.

Fair’s role is to fill that gap.

Houck explains that the company provides mechanical breakdown coverage, helping to cover repairs when a vehicle fails outside of an accident. This allows insurers, brokers, and carriers to offer a more complete solution to customers, rather than leaving them exposed to unexpected repair costs.

He adds that this type of coverage complements existing policies rather than replacing them.

By working alongside traditional auto insurance, Fair enables a more comprehensive approach to vehicle protection, which Houck believes aligns more closely with what consumers expect.

Houck also highlights the importance of distribution and partnerships in delivering these solutions.

At InsurTech NY, he says the focus is on meeting partners who can offer Fair’s products, as well as connecting with organisations that serve the same end customer. The event provides access to a wide range of stakeholders, including brokers, carriers, and technology providers, all in one place.

Looking at broader trends, Houck points to the growth of MGAs as a significant shift in the market.

He explains that MGAs are increasingly bringing specialised expertise to specific segments, such as commercial risk or high-risk auto. These organisations are able to underwrite and price risks in ways that larger carriers may not, while still relying on those carriers for capacity.

According to Houck, this is leading to the creation of more tailored and niche insurance programmes.

Overall, his view is that the market is becoming more flexible and specialised, with new models emerging to address gaps that traditional insurance has not fully covered.

Kelp DAO hits back at LayerZero for trying to shift the blame after a massive exploit

0

The popular Spiderman meme showing three identical superheroes pointing fingers at each other is having its crypto moment today.

Kelp DAO is set to push back on LayerZero’s post-mortem of Sunday’s $290 million exploit, which essentially blames Kelp, a L2 source familiar with the matter told CoinDesk. Kelp plans to dispute the cross-chain messaging firm’s claim that it ignored repeated warnings to move away from a single-verifier setup. CoinDesk has reviewed and verified the firm’s discussions.

Kelp is a liquid restaking protocol that takes user-deposited ether, routes it through a yield-generating system called EigenLayer, and issues a receipt token, rsETH, in exchange.

LayerZero is the cross-chain messaging infrastructure that moves rsETH between blockchains, using entities called DVNs (decentralized verifier networks) to verify whether a cross-chain transfer is valid.

On Saturday, attackers drained 116,500 rsETH, worth about $290 million, from Kelp’s LayerZero-powered bridge by poisoning the servers that LayerZero’s verifier relied on to check transactions.

Kelp, the source said, is planning on saying the DVN that was compromised via what it calls a “sophisticated state-sponsored attack” was LayerZero’s own infrastructure, not a third-party verifier.

Attackers compromised two of LayerZero’s own servers that check whether cross-chain transactions are legitimate, then flooded the backup servers with junk traffic to force LayerZero’s verifier onto the compromised ones.

All of that infrastructure was built and run by LayerZero, not Kelp, the source claimed.

The source contested LayerZero’s framing of the “1/1 configuration” as a fringe choice made against guidance. LayerZero’s post-mortem said KelpDAO chose a 1-of-1 DVN setup despite expressing recommendations to configure multi-DVN redundancy.

A “1/1 configuration” means only a single validator must sign off on a cross-chain message for the bridge to act on it, leaving the system with no second check to catch a compromised or forged instruction. A multi-validator configuration (such as 2/3, 3/5, etc.) ensures there is no single point of failure that can approve a forged message on its own.

They added that, through a direct communications channel with LayerZero, which has been open since July 2024, they produced no specific recommendation for Kelp to change the rsETH DVN configuration.

LayerZero’s own quickstart guide and default GitHub configuration point to a 1/1 DVN setup, the source told CoinDesk, adding 40% of protocols on LayerZero are currently using the same configuration.

The configuration Kelp ran also appears in LayerZero’s own V2 OApp Quickstart, where the sample layerzero.config.ts wires every pathway with one required DVN and no optional DVNs. That’s the same 1/1 structure.

Kelp’s core restaking contracts were not touched, and the exploit was isolated to the bridge layer, they added. Its emergency pause, 46 minutes after the drain, blocked two follow-up attempts that would have released an additional ~$200 million in rsETH.

CoinDesk reached out to LayerZero for comment on the story and didn’t hear back by the time of publication.

‘Deflecting responsibility’

Security researchers are also not buying LayerZero’s isolated framing, which pinned the blame on Kelp.

Kelp is a liquid restaking protocol. Its core competency is staking infrastructure, EigenLayer integration, and liquid staking token management. When integrating with LayerZero, Kelp relied on LayerZero’s documentation, their defaults, and their team’s guidance to make configuration decisions, the source claimed.

Yearn Finance core team developer Artem K, who is popularly known as @banteg on X, posted a technical review of LayerZero’s public deployment code and said that the reference setup ships with single-source verification defaults across every major chain, including Ethereum, BSC, Polygon, Arbitrum and Optimism.

That deployment also leaves a public endpoint exposed that leaks the list of configured servers to anyone who queries it.

Banteg flagged in his analysis that he can’t prove which configuration Kelp used, but noted that LayerZero usually asks new operators to use its default setup, which its post-mortem criticized.

Chainlink community manager Zach Rynes put it bluntly on X, alleging that LayerZero was “deflecting responsibility” for its own compromised infrastructure and accused the company of throwing Kelp under the bus for trusting a setup LayerZero itself supported.

As such, LayerZero has said it will no longer sign messages for any application running a single-verifier setup, forcing a protocol-wide migration.

In a statement on Monday afternoon on X, Kelp DAO confirmed CoinDesk’s earlier reporting and said the 1-of-1 DVN setup at the center of the incident reflects LayerZero’s documented default configuration. The team added that it has operated on LayerZero infrastructure since January 2024 and maintained close communication with the LayerZero team, including during its L2 expansion when, it says, the default configuration was explicitly confirmed as appropriate. “Establishing a shared and accurate account of what happened is the foundation for making the right fixes together,” the team wrote in their post.

For their part, the team behind LayerZero is working to “harden security across every possible vector for applications,” co-founder Bryan Pellegrino said in a post on X (formerly Twitter). He said that the initial investigations had been “largely resolved” and that the team would publish more updates soon.

Read more: ‘DeFi is dead’: crypto community scrambles after this year’s biggest hack exposes contagion risk

UPDATE (April 20, 2026, 21:27 UTC): Adds in Kelp DAO statement.

UPDATE (April 20, 2026, 21:45 UTC): Adds LayerZero statement.

DeFi Protocols Launch Joint Escape Hatch for Aave ETH Lenders and Loopers

0

Fluid’s aWETH Redemption Protocol, launched with Lido, Ether.fi, 1inch, 0x and Kyber, has processed $136M out of Aave’s frozen WETH pool in 48 hours.

The same architectural openness that turned a forged cross-chain message at Kelp DAO’s bridge into hundreds of millions of bad debt at Aave has in 48 hours produced its own antidote: A coalition of DeFi protocols has launched an emergency exit route.

Fluid, a DeFi DEX and lending protocol, has joined with other DeFi protocols to build a way for ETH depositors and loopers on Aave to swap their positions out of WETH, either exiting the protocol altogether or switching to a different collateral type, at a time when direct withdrawals are unavailable after the $290 million Kelp DAO exploit.

The aWETH Redemption Protocol has processed 58,510 aWETH, or approximately $136 million, out of Aave’s frozen WETH pool in its first 48 hours, according to the live Dune dashboard Fluid is publishing.

The protocol was built in under 24 hours in response to Aave’s ETH utilization hitting 100% after the April 18 exploit of Kelp DAO’s rsETH bridge adapter.

How it works

The infrastructure allows Aave ETH lenders to swap aWETH into wstETH or weETH collateral in a single transaction, at a discount of roughly 2.21% for a 1,000 aWETH swap, per 1inch co-founder Sergej Kunz. Early exits via secondary markets had been clearing near 23% below par.

Two user scenarios are supported: For lenders, aWETH converts to wstETH and weETH collateral. Users can then withdraw their assets. For borrowers, collateral switches from ETH to wstETH or weETH collateral. Debt remains unchanged and users can exit a previously stuck position or remain on Aave with yield-bearing collateral.

Lenders hand aWETH into Fluid’s Lite ETH Vault in exchange for wstETH or weETH. The vault then uses the incoming aWETH to repay part of its own WETH debt at Aave, extinguishing a liability without requiring WETH to leave Aave’s pool. The netting works because Fluid is the single largest user of the Aave WETH market, carrying approximately $1.5 billion in ETH debt against its looped Lite Vault positions.

Because Fluid already owes the debt being retired, the protocol is not taking on new directional risk. It is exchanging one claim on LST collateral for another, with the exiting lender absorbing a modest haircut and the vault reducing its borrowed exposure in a market where supply is otherwise trapped.

Lido Finance, Ether.fi, 0x Protocol, 1inch, and KyberNetwork are leveraging the protocol. Lido and Ether.fi contribute LST liquidity, 1inch shipped the front-end, and 0x and Kyber are routing orders. Aave’s DAO-recommended withdrawal guidance now directs trapped WETH suppliers toward the Fluid route.

“ETH utilization on Aave hit 100% and lenders had no exit. Fluid built the infrastructure in hours — with significant capacity to support ETH lenders at scale,” Fluid Founder and CTO Samyak Jain said in an announcement.

Kelp DAO exploit context

On April 18, an attacker exploited Kelp DAO’s LayerZero-based rsETH bridge adapter and minted 116,500 rsETH, approximately $293 million, or 18% of circulating supply, without a corresponding amount locked on the Ethereum side. The attacker supplied the unbacked rsETH as collateral on Aave V3 and V4 and borrowed approximately $236 million in WETH before markets were frozen.

Aave’s WETH utilization reached 100% within hours as lenders attempted to withdraw ahead of the bad-debt recognition, breaking the lending invariant that allows passive withdrawals. Variable borrow rates spiked into triple digits and aWETH began trading at a discount on secondary markets.

Aave’s risk team, in its April 20 incident report, modeled bad debt at between $123.7 million and $230.1 million depending on how claims on the under-collateralized rsETH L2 adapter are allocated.

Kelp DAO and LayerZero have continued to dispute responsibility. Kelp’s April 19 statement argued that the 1-of-1 DVN configuration used on the bridge was LayerZero’s documented default in its quickstart guide and was re-confirmed as appropriate by the LayerZero team during Kelp’s L2 expansion. LayerZero has attributed the exploit to the North Korea-linked Lazarus Group’s TraderTraitor subgroup and said it will no longer allow new OFT deployments to ship with 1-of-1 DVN configurations.

The composability dimension

The architectural property that allowed the exploit to cascade across Aave, Compound, Fluid and other venues is what allowed the redemption protocol to be assembled in under a day. aWETH is a standardized receipt token, wstETH and weETH are standardized LSTs, Aave’s “repaywithAtokens” function is public and permissionless, and aggregators can source liquidity from any venue. The Fluid flow combines those primitives without a governance vote, a treasury drawdown, or a new counterparty relationship.

The protocol does not reduce Aave’s modeled bad debt, reverse the attacker’s borrowing, or affect the LayerZero-Kelp dispute. It provides an individual exit for lenders who would otherwise wait for a socialization outcome or accept a steeper market discount.

Fluid said capacity is significant and additional partners are being engaged.

New evidence backs hologic’s AI-powered mammography technology for detecting challenging cancers

0

Results highlight AI’s potential to aid radiologists in identifying diverse breast cancer subtypes, including invasive lobular cancer

Results highlight AI’s potential to aid radiologists in identifying diverse breast cancer subtypes, including invasive lobular cancer

New research on Hologic’s AI-driven breast cancer detection technologies, including a study focused on invasive lobular cancer, was presented at the Society of Breast Imaging (SBI) Symposium over the weekend in Seattle, Washington.

New research highlights AI’s potential to aid radiologists in identifying diverse breast cancer subtypes, including invasive lobular cancerShare

“Invasive lobular cancers are more challenging to detect on a mammogram because of their unique characteristics,” said Mark Horvath, President of Breast & Skeletal Health Solutions at Hologic. “In the study, AI maintained high sensitivity for flagging these cancers, including some that had been interpreted as negative at a prior screening. These data add to a growing body of evidence that AI can act as a powerful supportive tool for radiologists as they review the full spectrum of breast cancers.”

In this retrospective, single-center study, researchers at Massachusetts General Hospital in Boston reviewed invasive lobular cancer cases diagnosed over a 10-year period and grouped them into two categories: those detected by a radiologist during a routine screening exam (195 total) and “false negatives” that were diagnosed within a year of a routine screening exam initially interpreted as negative (44 total). Researchers then used Hologic’s Genius AI® Detection solution to retrospectively analyze all 239 cases. In this cohort, the technology identified and correctly localized close to 90% of the confirmed invasive lobular cancers.1

New research suggests that, on average, 1 in 20 women worldwide will be diagnosed with breast cancer in their lifetime and, that if current rates continue, by 2050 there will be 3.2 million new breast cancer cases and 1.1 million breast cancer-related deaths per year.2 About 10-15% of all breast cancers are invasive lobular cancers,3 while ductal cancers that originate in the milk ducts of the breast — such as invasive ductal carcinoma and ductal carcinoma in situ — occur more commonly. Invasive lobular cancer arises in the milk-producing glands (lobules) of the breast and, because of its unique biology and tendency to grow in a linear pattern, it may be more challenging to see on mammography. This may lead to later detection and a more advanced stage at diagnosis.

The AI algorithm also identified 43% of the invasive lobular cancer cases initially interpreted during routine screening as negative.1 Of note, as a retrospective analysis at a single institution, the study did not evaluate how use of AI in real time clinical practice would affect recall rates, biopsy outcomes or patient management.

Also at the Society of Breast Imaging Symposium, Hologic hosted a lunch and learn discussion with breast imaging experts focused on implementation of 3DQuorum® imaging technology, which uses AI to reduce the number of 3D imaging “slices” radiologists need to review without compromising image quality, sensitivity or accuracy.4,5

Study Limitations

The MGH study did not assess false-positive rates, recall rates or biopsy outcomes, and its single-center design may limit generalizability. AI performance was evaluated retrospectively and did not influence real-time radiologist decision-making; therefore, the observed gains represent a theoretical upper bound rather than a measured clinical impact. Additionally, the cohort included only patients with invasive lobular cancer, precluding comparison with other histologic subtypes.

Strategy (MSTR) Makes $2.5B Bitcoin Buy, 3rd Largest To Date

0

Strategy added 34,164 bitcoin to its treasury last week, spending about $2.54 billion in one of the largest single purchases in its history, according to a Monday regulatory filing.

The acquisition was made at an average price of $74,395 per bitcoin and brings the company’s total holdings to 815,061 BTC. Strategy has now spent roughly $61.56 billion accumulating bitcoin at an average cost basis of $75,527 per coin. This is Strategy’s third largest bitcoin purchase.

With bitcoin trading near $75,000, the firm’s position sits close to its aggregate purchase price, leaving the holdings near break-even after recent market volatility.

Strategy has overtaken BlackRock in total bitcoin holdings with this latest purchase.The firm led by Michael Saylor now holds 815,061 BTC, surpassing BlackRock’s 802,823 BTC, which is primarily held through its spot bitcoin ETF products.