Kelp DAO Disputes LayerZero's Claims Over $290 Million Exploit

A recent cryptocurrency exploit has sparked a heated debate between Kelp DAO and LayerZero, with Kelp set to challenge LayerZero's account of the $290 million disaster. According to a source familiar with the matter, Kelp plans to argue that the compromised verifier was part of LayerZero's own infrastructure, and that the setup in question was LayerZero's default configuration. This development has led to a wider discussion about the security of cross-chain messaging and the responsibility that comes with it. Kelp, a liquid restaking protocol, takes user-deposited ether and issues a receipt token, rsETH, in exchange, which is then moved between blockchains using LayerZero's infrastructure. The exploit in question saw attackers drain 116,500 rsETH, worth about $290 million, from Kelp's LayerZero-powered bridge by poisoning the servers that LayerZero's verifier relied on. Kelp claims that the compromised verifier was not a third-party entity, but rather LayerZero's own infrastructure, and that the setup that was exploited was the default configuration provided by LayerZero. The source also contested LayerZero's claim that Kelp chose a 1-of-1 DVN setup despite recommendations to configure multi-DVN redundancy, arguing that LayerZero's own quickstart guide and default GitHub configuration point to a 1/1 DVN setup. Furthermore, the source noted that 40% of protocols on LayerZero are currently using the same configuration. Security researchers have also questioned LayerZero's account of the incident, with some accusing the company of deflecting responsibility for its own compromised infrastructure. As the debate continues, both Kelp and LayerZero are working to address the security concerns and prevent similar incidents in the future.