Kelp DAO Disputes LayerZero's Claims Over $290 Million Exploit, Citing Default Settings as Cause

A recent crypto controversy has sparked a heated debate, with Kelp DAO set to challenge LayerZero's account of the $290 million exploit that occurred on Sunday. According to a source familiar with the matter, Kelp plans to argue that the compromised verifier was actually part of LayerZero's own infrastructure and that the setup was based on LayerZero's default configuration. The incident has led to a blame game between the two parties, with Kelp claiming that LayerZero's default settings were the root cause of the exploit. The situation is being closely watched by the crypto community, with many experts weighing in on the matter. Kelp, a liquid restaking protocol, takes user-deposited ether and routes it through a yield-generating system called EigenLayer, issuing a receipt token, rsETH, in exchange. LayerZero, on the other hand, provides the cross-chain messaging infrastructure that moves rsETH between blockchains, using entities called DVNs to verify the validity of cross-chain transfers. The attackers exploited the system by poisoning the servers that LayerZero's verifier relied on, draining 116,500 rsETH, worth around $290 million, from Kelp's LayerZero-powered bridge. Kelp claims that the compromised DVN was LayerZero's own infrastructure and that the setup was based on LayerZero's default configuration, which is used by around 40% of protocols on the platform. The incident has raised questions about the security of cross-chain messaging infrastructure and the need for more robust verification mechanisms. As the situation continues to unfold, it remains to be seen how the two parties will resolve their differences and what measures will be taken to prevent similar incidents in the future.