Kelp DAO Disputes LayerZero's Account of $290 Million Exploit, Citing Default Settings as the Cause
A recent cryptocurrency incident has sparked a heated debate, with Kelp DAO and LayerZero trading blame for a $290 million exploit. According to a source familiar with the matter, Kelp DAO plans to dispute LayerZero's claim that it ignored warnings about its single-verifier setup. Instead, Kelp DAO claims that the compromised verifier was part of LayerZero's own infrastructure and that the setup was based on LayerZero's default configuration. The incident occurred when attackers drained 116,500 rsETH, worth about $290 million, from Kelp's LayerZero-powered bridge by poisoning the servers that LayerZero's verifier relied on to check transactions. Kelp DAO argues that it relied on LayerZero's documentation and defaults when configuring its setup, and that the company's post-mortem report unfairly blames Kelp for the exploit. Security researchers have also questioned LayerZero's account of the incident, with one expert noting that LayerZero's default setup leaves a public endpoint exposed, potentially allowing attackers to access sensitive information. The incident has sparked a wider debate about the security of cryptocurrency infrastructure and the need for greater transparency and accountability in the industry.