Kelp DAO Disputes LayerZero's Claims Over $290 Million Exploit
A recent cryptocurrency exploit has sparked a heated debate between Kelp DAO and LayerZero, with each party blaming the other for the massive $290 million loss. The incident occurred when attackers drained 116,500 rsETH, worth approximately $290 million, from Kelp's LayerZero-powered bridge by compromising the servers that LayerZero's verifier relied on to check transactions. Kelp DAO claims that the compromised verifier was part of LayerZero's own infrastructure, not a third-party verifier, and that the setup was based on LayerZero's default configuration. According to Kelp, the configuration was not a fringe choice made against guidance, but rather the default setup provided by LayerZero. The company's quickstart guide and default GitHub configuration point to a 1/1 DVN setup, which is the same configuration used by 40% of protocols on LayerZero. Security researchers have also questioned LayerZero's framing of the incident, with some accusing the company of deflecting responsibility for its own compromised infrastructure. The incident has sparked a wider debate about the security of cross-chain messaging protocols and the need for greater transparency and accountability in the industry. As the situation continues to unfold, both Kelp DAO and LayerZero have pledged to work together to establish a shared understanding of what happened and to implement fixes to prevent similar incidents in the future.