Kelp DAO Disputes LayerZero's Claims Regarding $290 Million Exploit

A recent $290 million disaster has sparked a heated debate between Kelp DAO and LayerZero, with each party blaming the other for the massive loss. Kelp DAO, a liquid restaking protocol, claims that the compromised verifier was actually part of LayerZero's own infrastructure. Furthermore, Kelp asserts that the setup it was criticized for was, in fact, LayerZero's default configuration. This incident has led to a significant loss, with attackers draining 116,500 rsETH, worth approximately $290 million, from Kelp's LayerZero-powered bridge. The attack was made possible by poisoning the servers that LayerZero's verifier relied on to check transactions. According to Kelp, the compromised entities, known as decentralized verifier networks (DVNs), were part of LayerZero's infrastructure, not third-party verifiers. The attackers exploited two of LayerZero's own servers, then flooded the backup servers with junk traffic to force LayerZero's verifier onto the compromised ones. Kelp disputes LayerZero's claim that it ignored repeated warnings to move away from a single-verifier setup, stating that the configuration it used was based on LayerZero's default settings. In fact, Kelp claims that 40% of protocols on LayerZero are currently using the same configuration. Security researchers have also questioned LayerZero's framing of the incident, with some accusing the company of deflecting responsibility for its own compromised infrastructure. The incident has led to a wider discussion about the security risks associated with cross-chain messaging and the need for more robust verification processes. As the situation continues to unfold, both Kelp DAO and LayerZero are working to address the issues and prevent similar incidents in the future.