Kelp DAO Disputes LayerZero's Claims Regarding $290 Million Incident
A recent $290 million disaster has sparked a heated debate between Kelp DAO and LayerZero, with each side pointing fingers at the other. Kelp DAO is pushing back against LayerZero's claims that it was responsible for the incident due to its use of a single-verifier setup. Instead, Kelp DAO argues that the compromised verifier was part of LayerZero's own infrastructure, and the setup that was allegedly at fault was actually the default configuration provided by LayerZero. According to a source familiar with the matter, Kelp DAO plans to dispute LayerZero's post-mortem of the incident, which blamed Kelp for ignoring repeated warnings to move away from a single-verifier setup. The incident occurred when attackers drained 116,500 rsETH, worth about $290 million, from Kelp's LayerZero-powered bridge by poisoning the servers that LayerZero's verifier relied on to check transactions. Kelp DAO claims that the infrastructure that was compromised was built and run by LayerZero, not Kelp. The source also contested LayerZero's framing of the '1/1 configuration' as a fringe choice made against guidance, stating that LayerZero's own quickstart guide and default GitHub configuration point to a 1/1 DVN setup, and that 40% of protocols on LayerZero are currently using the same configuration. Security researchers have also come to Kelp DAO's defense, with one stating that LayerZero's isolated framing of the incident, which pinned the blame on Kelp, is not accurate. The incident has sparked a wider debate about the security of cross-chain messaging protocols and the need for greater transparency and accountability in the industry.