Kelp DAO Disputes LayerZero's Claims Regarding $290 Million Exploit
A recent cryptocurrency exploit has sparked a heated debate between Kelp DAO and LayerZero, with Kelp set to challenge LayerZero's account of the $290 million disaster. According to a source familiar with the matter, Kelp plans to argue that the compromised verifier was actually part of LayerZero's own infrastructure and that the setup in question was the default configuration provided by LayerZero. The incident occurred when attackers drained 116,500 rsETH, worth approximately $290 million, from Kelp's LayerZero-powered bridge by poisoning the servers used by LayerZero's verifier. Kelp claims that the attack was made possible by a sophisticated state-sponsored attack on LayerZero's servers, which were built and run by LayerZero, not Kelp. The source also contested LayerZero's claim that Kelp chose a 1-of-1 DVN setup despite recommendations to configure multi-DVN redundancy, pointing out that LayerZero's own quickstart guide and default GitHub configuration recommend a 1/1 DVN setup. In fact, 40% of protocols on LayerZero are currently using the same configuration. Security researchers have also expressed skepticism about LayerZero's account, with one noting that the reference setup for LayerZero's public deployment code ships with single-source verification defaults across every major chain. The incident has led to a wider debate about the security of cryptocurrency protocols and the need for greater transparency and accountability. As the situation continues to unfold, both Kelp DAO and LayerZero have released statements, with Kelp emphasizing the importance of establishing a shared and accurate account of what happened and LayerZero announcing plans to harden security across every possible vector for applications.