Kelp DAO Disputes LayerZero's Claims Over $290 Million Exploit

A recent cryptocurrency exploit has sparked a heated debate between Kelp DAO and LayerZero, with each party assigning blame to the other. The incident in question involved a $290 million loss due to a compromised verifier. According to Kelp DAO, the compromised verifier was not a third-party entity, but rather part of LayerZero's own infrastructure. Furthermore, Kelp DAO claims that the setup that was exploited was based on LayerZero's default configuration, which was provided in their documentation and quickstart guide. This configuration, known as a 1/1 setup, relies on a single verifier to validate cross-chain transactions. Kelp DAO argues that this setup was not a fringe choice, but rather the recommended configuration provided by LayerZero. In fact, 40% of protocols on LayerZero are currently using this same configuration. The incident has raised questions about the security of cross-chain messaging infrastructure and the need for more robust verification processes. Security researchers have also weighed in on the debate, with some accusing LayerZero of deflecting responsibility for the exploit. As the situation continues to unfold, both Kelp DAO and LayerZero have released statements, with Kelp DAO emphasizing the need for a shared and accurate account of what happened, and LayerZero announcing plans to harden security across all possible vectors for applications.