Kelp DAO Disputes LayerZero's Claims Regarding $290 Million Disaster

A recent cryptocurrency incident has sparked a heated debate between Kelp DAO and LayerZero, with Kelp planning to refute LayerZero's post-mortem analysis of the $290 million exploit. According to a source familiar with the matter, Kelp will claim that the compromised verifier was actually part of LayerZero's own infrastructure, and the setup that was criticized was LayerZero's default onboarding configuration. The incident involved the exploitation of Kelp's LayerZero-powered bridge, resulting in the theft of 116,500 rsETH, valued at approximately $290 million. Kelp, a liquid restaking protocol, had been using LayerZero's cross-chain messaging infrastructure to move rsETH between blockchains. However, the source revealed that the attackers compromised two of LayerZero's own servers, which were used to verify cross-chain transactions, and then flooded the backup servers with junk traffic to force LayerZero's verifier onto the compromised ones. Kelp plans to argue that the '1/1 configuration' criticized by LayerZero was actually the default setup recommended by LayerZero, and that 40% of protocols on the platform are currently using the same configuration. The incident has sparked a wider debate about the security of cross-chain messaging infrastructure and the need for more robust verification processes. Security researchers have also weighed in, with some accusing LayerZero of deflecting responsibility for the incident. As the situation continues to unfold, both Kelp DAO and LayerZero have released statements, with Kelp confirming that it had been using LayerZero's default configuration and LayerZero announcing plans to 'harden security across every possible vector for applications'.