Kelp DAO Blames LayerZero's Default Settings for $290 Million Disaster
A recent cryptocurrency exploit has sparked a heated debate between Kelp DAO and LayerZero, with each side pointing fingers at the other. The incident in question involved a $290 million disaster that occurred when attackers drained 116,500 rsETH from Kelp's LayerZero-powered bridge. According to Kelp DAO, the compromised verifier was not a third-party entity, but rather part of LayerZero's own infrastructure. Furthermore, Kelp claims that the setup that was exploited was based on LayerZero's default configuration, which was never explicitly warned against. In fact, LayerZero's own quickstart guide and default GitHub configuration point to a 1/1 DVN setup, which is the same configuration that Kelp used. This has led many in the cryptocurrency community to accuse LayerZero of deflecting responsibility for its own compromised infrastructure and throwing Kelp under the bus for trusting a setup that LayerZero itself supported. As the situation continues to unfold, both parties are working to establish a shared understanding of what happened and to implement fixes to prevent similar incidents in the future.