Kelp DAO Disputes LayerZero's Claim of Responsibility in $290 Million Crypto Heist
A recent $290 million cryptocurrency heist has sparked a heated debate between Kelp DAO and LayerZero, with each party shifting the blame to the other. Kelp DAO, a liquid restaking protocol, claims that the compromised verifier was part of LayerZero's own infrastructure and that the setup in question was the default configuration provided by LayerZero. According to Kelp DAO, LayerZero's cross-chain messaging infrastructure was at fault, as it used a single-verifier setup that was vulnerable to attack. The incident occurred when attackers drained 116,500 rsETH, worth approximately $290 million, from Kelp's LayerZero-powered bridge by poisoning the servers that LayerZero's verifier relied on to check transactions. Kelp DAO argues that it had been using LayerZero's default settings and had not been explicitly warned to change the configuration. The dispute highlights the complexities of cryptocurrency security and the need for clear communication and accountability between protocols. Security researchers have also weighed in on the issue, with some suggesting that LayerZero's default settings and lack of clear guidance may have contributed to the exploit. The incident has sparked a wider discussion about the risks and challenges associated with cryptocurrency and the need for increased security measures to protect users' assets.