Kelp DAO Challenges LayerZero's Account of $290 Million Exploit

A recent cryptocurrency exploit has sparked a heated debate between Kelp DAO and LayerZero, with each side blaming the other for the massive $290 million loss. The incident occurred when attackers drained 116,500 rsETH, worth approximately $290 million, from Kelp's LayerZero-powered bridge by compromising the servers that LayerZero's verifier relied on to check transactions. Kelp DAO claims that the compromised verifier was part of LayerZero's own infrastructure, not a third-party verifier, and that the setup it was using was LayerZero's default configuration. According to Kelp DAO, the configuration it used was recommended by LayerZero and was not against their guidance. In fact, 40% of protocols on LayerZero are currently using the same configuration. Security researchers have also questioned LayerZero's account of the incident, with one researcher pointing out that LayerZero's reference setup ships with single-source verification defaults across every major chain. The incident has led to a protocol-wide migration, with LayerZero announcing that it will no longer sign messages for any application running a single-verifier setup. Both Kelp DAO and LayerZero have stated that they are working to improve security and establish a shared understanding of what happened.