Kelp DAO Shifts Blame to LayerZero for $290 Million Disaster, Citing Default Settings
A recent cryptocurrency exploit has sparked a heated debate between Kelp DAO and LayerZero, with each side pointing fingers at the other. The incident in question involved the theft of $290 million worth of rsETH, a receipt token issued by Kelp DAO. According to Kelp, the compromised verifier was part of LayerZero's own infrastructure, and the setup that was faulted for the exploit was actually LayerZero's default configuration. This configuration, known as a 1/1 setup, relies on a single verifier to validate cross-chain transactions. Kelp claims that it was following LayerZero's recommended settings and that the company's own quickstart guide and GitHub configuration point to this setup. In fact, 40% of protocols on LayerZero are currently using the same configuration. Security researchers have also questioned LayerZero's decision to blame Kelp for the exploit, with some accusing the company of deflecting responsibility. As the situation continues to unfold, both Kelp DAO and LayerZero are working to address the issue and prevent similar incidents in the future. Kelp has stated that it will work with LayerZero to establish a shared understanding of what happened and to implement fixes. Meanwhile, LayerZero has announced that it will no longer support single-verifier setups and is working to harden security across all possible vectors for applications.