Kelp DAO Disputes LayerZero's Claims Over $290 Million Exploit

A recent cryptocurrency exploit has sparked a heated debate between Kelp DAO and LayerZero, with each side pointing fingers at the other. The incident, which resulted in a $290 million loss, has been blamed by LayerZero on Kelp DAO's allegedly flawed configuration. However, Kelp DAO is pushing back, claiming that the compromised verifier was actually LayerZero's own infrastructure and that the setup it was faulted for running was LayerZero's onboarding default. According to a source familiar with the matter, Kelp plans to dispute LayerZero's post-mortem of the incident, which essentially blames Kelp for ignoring repeated warnings to move away from a single-verifier setup. Kelp is a liquid restaking protocol that takes user-deposited ether, routes it through a yield-generating system, and issues a receipt token in exchange. LayerZero, on the other hand, is the cross-chain messaging infrastructure that moves these tokens between blockchains using entities called decentralized verifier networks to verify cross-chain transfers. The attack, which occurred on Saturday, saw attackers drain 116,500 receipt tokens, worth about $290 million, from Kelp's LayerZero-powered bridge by poisoning the servers that LayerZero's verifier relied on to check transactions. Kelp claims that the decentralized verifier network that was compromised was LayerZero's own infrastructure, not a third-party verifier, and that the setup it was running was LayerZero's default configuration. Security researchers have also questioned LayerZero's framing of the incident, with one researcher pointing out that LayerZero's own quickstart guide and default GitHub configuration point to a single-verifier setup, which is the same configuration that Kelp was running. The researcher added that 40% of protocols on LayerZero are currently using the same configuration. The incident has sparked a wider debate about the security of cryptocurrency protocols and the need for greater transparency and accountability. As the situation continues to unfold, it remains to be seen how the incident will be resolved and what measures will be taken to prevent similar exploits in the future.