Kelp DAO Challenges LayerZero's Account of $290 Million Exploit, Citing Default Settings

A recent cryptocurrency exploit has sparked a heated debate between Kelp DAO and LayerZero, with each side pointing fingers at the other. The incident in question involved a $290 million loss due to a compromised verifier. According to Kelp DAO, the compromised entity was actually part of LayerZero's infrastructure, and the setup that was allegedly faulty was, in fact, the default configuration provided by LayerZero. Kelp DAO is a liquid restaking protocol that utilizes LayerZero's cross-chain messaging infrastructure to move its receipt token, rsETH, between blockchains. The attack occurred when hackers drained 116,500 rsETH from Kelp's bridge by poisoning the servers that LayerZero's verifier relied on. Kelp DAO claims that it was not at fault and that the blame lies with LayerZero's own infrastructure and default settings. The company argues that it had been using LayerZero's recommended configuration and had not been warned about any potential risks. Security researchers have also weighed in on the issue, with some stating that LayerZero's default setup is flawed and that the company is trying to deflect responsibility. As the situation continues to unfold, both Kelp DAO and LayerZero are working to address the security concerns and prevent similar incidents in the future.