Kelp DAO disputes LayerZero's account of $290 million exploit, cites 'default' settings as cause
A recent $290 million disaster has sparked a heated debate between Kelp DAO and LayerZero, with each side pointing fingers at the other. According to sources, Kelp DAO is preparing to challenge LayerZero's post-mortem analysis of the incident, which blamed Kelp for ignoring warnings about its single-verifier setup. Kelp, a liquid restaking protocol, takes user-deposited ether and issues a receipt token called rsETH, which is then moved between blockchains using LayerZero's cross-chain messaging infrastructure. However, the protocol claims that the compromised verifier was actually part of LayerZero's own infrastructure, and that the setup was based on LayerZero's default configuration. The incident occurred when attackers drained 116,500 rsETH, worth around $290 million, from Kelp's LayerZero-powered bridge by poisoning the servers that LayerZero's verifier relied on. Kelp argues that it was not at fault, as the infrastructure was built and run by LayerZero, and that the default settings provided by LayerZero were followed. Security researchers have also questioned LayerZero's account, with one expert noting that the reference setup provided by LayerZero ships with single-source verification defaults across every major chain. The debate highlights the complexities of cross-chain messaging and the need for clear accountability in the event of security breaches. As the situation continues to unfold, both Kelp DAO and LayerZero are working to address the issues and prevent similar incidents in the future.