Kelp DAO Disputes LayerZero's Claims Over $290 Million Exploit
A recent cryptocurrency exploit has sparked a heated debate between Kelp DAO and LayerZero, with each party shifting blame for the massive $290 million disaster. The incident occurred when attackers drained 116,500 rsETH, worth approximately $290 million, from Kelp's LayerZero-powered bridge by compromising LayerZero's verifier. Kelp DAO claims that the compromised verifier was part of LayerZero's own infrastructure, and the setup was based on LayerZero's default configuration. According to Kelp, the configuration was not a fringe choice made against guidance, but rather a setup that was built and run by LayerZero. The company argues that LayerZero's post-mortem report unfairly blamed Kelp for ignoring repeated warnings to move away from a single-verifier setup. Kelp plans to dispute these claims, stating that it relied on LayerZero's documentation, defaults, and team guidance to make configuration decisions. Security researchers have also questioned LayerZero's framing of the incident, with some accusing the company of deflecting responsibility for its own compromised infrastructure. The incident has led to a protocol-wide migration, with LayerZero announcing that it will no longer sign messages for any application running a single-verifier setup. As the situation continues to unfold, both parties are working to establish a shared and accurate account of what happened, with the goal of making the necessary fixes to prevent similar incidents in the future.