Kelp DAO Disputes LayerZero's Account of $290 Million Crypto Heist
A recent cryptocurrency exploit has sparked a heated debate between Kelp DAO and LayerZero, with each party pointing fingers at the other. The incident in question involved the theft of approximately $290 million worth of rsETH, a receipt token issued by Kelp DAO, from a LayerZero-powered bridge. According to Kelp DAO, the compromised verifier was part of LayerZero's own infrastructure, and the setup that was faulted for the exploit was actually LayerZero's default configuration. This claim challenges LayerZero's initial account of the incident, which placed the blame on Kelp DAO for allegedly ignoring warnings to move away from a single-verifier setup. Kelp DAO plans to argue that the default settings provided by LayerZero, which 40% of protocols on the platform are currently using, are the root cause of the problem. The dispute highlights the challenges of assigning responsibility in the complex and interconnected world of cryptocurrency. Security researchers have also weighed in on the debate, with some suggesting that LayerZero's account of the incident is an attempt to deflect responsibility for its own compromised infrastructure. As the situation continues to unfold, both Kelp DAO and LayerZero are working to address the security concerns and prevent similar incidents in the future.