Kelp DAO Disputes LayerZero's Account of $290 Million Exploit, Citing Default Settings as the Root Cause
A recent cryptocurrency exploit has sparked a heated debate between Kelp DAO and LayerZero, with Kelp set to challenge LayerZero's post-mortem analysis of the $290 million disaster. According to a source familiar with the matter, Kelp plans to argue that the compromised verifier was part of LayerZero's own infrastructure, and that the setup it used was the default configuration provided by LayerZero. The incident occurred when attackers drained 116,500 rsETH, worth approximately $290 million, from Kelp's LayerZero-powered bridge by poisoning the servers that LayerZero's verifier relied on to verify transactions. Kelp claims that the infrastructure was built and run by LayerZero, not by Kelp, and that the '1/1 configuration' used was the default setup recommended by LayerZero. Security researchers have also questioned LayerZero's account of the incident, with some accusing the company of deflecting responsibility for its own compromised infrastructure. The debate highlights the complexities and risks associated with cross-chain messaging and the need for greater transparency and accountability in the cryptocurrency space.