Kelp DAO Disputes LayerZero's Claims Regarding $290 Million Disaster
A recent cryptocurrency exploit has sparked a heated debate between Kelp DAO and LayerZero, with Kelp set to challenge LayerZero's account of the $290 million disaster. According to a source familiar with the matter, Kelp plans to argue that the compromised verifier was actually part of LayerZero's own infrastructure, and that the setup it used was LayerZero's default configuration. The incident occurred when attackers poisoned the servers that LayerZero's verifier relied on, draining 116,500 rsETH, worth around $290 million, from Kelp's bridge. Kelp claims that it was following LayerZero's recommended setup, which included a single-verifier configuration. However, LayerZero has stated that it had warned Kelp about the risks of using this setup and that Kelp had chosen to ignore these warnings. Security researchers have also questioned LayerZero's account of the incident, with one developer pointing out that LayerZero's default setup includes single-source verification defaults across multiple chains. The incident has led to a wider debate about the security of cryptocurrency protocols and the need for greater transparency and accountability. In a statement, Kelp DAO confirmed that it had been using LayerZero's default configuration and that it had maintained close communication with the LayerZero team. LayerZero has announced that it will no longer support single-verifier setups and will be working to improve the security of its infrastructure.