Kelp DAO Disputes LayerZero's Account of $290 Million Exploit, Citing Default Settings as Culprit
A recent cryptocurrency exploit has sparked a heated debate between Kelp DAO and LayerZero, with Kelp set to dispute LayerZero's post-mortem of the $290 million disaster. According to a source familiar with the matter, Kelp plans to argue that the compromised verifier was part of LayerZero's own infrastructure, not a third-party verifier, and that the setup was based on LayerZero's default configuration. The exploit occurred when attackers drained 116,500 rsETH, worth about $290 million, from Kelp's LayerZero-powered bridge by poisoning the servers that LayerZero's verifier relied on to check transactions. Kelp claims that the compromised infrastructure was built and run by LayerZero, and that the 1/1 configuration used was the default setup recommended by LayerZero. Security researchers have also questioned LayerZero's account of the incident, with some alleging that the company is deflecting responsibility for its own compromised infrastructure. The incident has sparked a wider debate about the security of cryptocurrency protocols and the need for greater transparency and accountability.