Kelp DAO Disputes LayerZero's Claim of Fault in $290 Million Disaster
A recent crypto controversy is unfolding, with Kelp DAO set to challenge LayerZero's account of the $290 million exploit that occurred on Sunday. According to a source familiar with the matter, Kelp plans to argue that the compromised verifier was actually part of LayerZero's own infrastructure, and that the setup in question was the default configuration provided by LayerZero. The incident has sparked a heated debate, with security researchers and other experts weighing in on the matter. Kelp, a liquid restaking protocol, had been using LayerZero's cross-chain messaging infrastructure to move its receipt token, rsETH, between blockchains. However, on Saturday, attackers drained 116,500 rsETH, worth approximately $290 million, from Kelp's LayerZero-powered bridge by poisoning the servers that LayerZero's verifier relied on to check transactions. Kelp claims that the attackers compromised two of LayerZero's own servers, which were then used to flood the backup servers with junk traffic, forcing LayerZero's verifier onto the compromised ones. The source contested LayerZero's claim that Kelp chose a 1-of-1 DVN setup despite recommendations to configure multi-DVN redundancy, arguing that LayerZero's own quickstart guide and default GitHub configuration point to a 1/1 DVN setup, and that 40% of protocols on LayerZero are currently using the same configuration. Security researchers, including Yearn Finance core team developer Artem K, have also questioned LayerZero's framing of the incident, with some accusing the company of deflecting responsibility for its own compromised infrastructure. The controversy has led to a wider discussion about the security risks associated with cross-chain messaging protocols and the importance of transparent communication between companies and their users.