Kelp DAO Disputes LayerZero's Claims Regarding $290 Million Exploit
A recent cryptocurrency exploit has sparked a heated debate between Kelp DAO and LayerZero, with each party blaming the other for the massive $290 million loss. According to sources familiar with the matter, Kelp DAO plans to refute LayerZero's claims that it was responsible for the exploit due to its use of a single-verifier setup. Instead, Kelp DAO asserts that the compromised verifier was part of LayerZero's own infrastructure and that the setup was based on LayerZero's default configuration. The incident occurred when attackers drained 116,500 rsETH, worth approximately $290 million, from Kelp's LayerZero-powered bridge by compromising LayerZero's servers. Kelp DAO claims that it relied on LayerZero's documentation and guidance when configuring its setup and that the 1/1 configuration was not a fringe choice, but rather the default setup recommended by LayerZero. Security researchers have also questioned LayerZero's narrative, with some accusing the company of deflecting responsibility for its own compromised infrastructure. The incident has led to a broader discussion about the security risks associated with cross-chain messaging protocols and the need for more robust security measures to prevent such exploits in the future.