Kelp DAO Disputes LayerZero's Account of $290 Million Exploit, Citing Default Settings as the Cause
A recent $290 million exploit has sparked a dispute between Kelp DAO and LayerZero, with Kelp set to contest LayerZero's post-mortem analysis. According to a source familiar with the matter, Kelp will argue that the compromised verifier was part of LayerZero's own infrastructure, not a third-party entity. The issue arose when attackers drained 116,500 rsETH, worth around $290 million, from Kelp's LayerZero-powered bridge by poisoning the servers that LayerZero's verifier relied on. Kelp claims that the setup, which used a single-verifier configuration, was based on LayerZero's default settings and that the company had not provided specific recommendations to change the configuration. The incident has raised questions about the security of cross-chain messaging infrastructure and the responsibility of companies like LayerZero to ensure the safety of their protocols. Security researchers have also weighed in, criticizing LayerZero's response and suggesting that the company is deflecting responsibility for its own compromised infrastructure. As the situation continues to unfold, both Kelp DAO and LayerZero have released statements, with Kelp emphasizing the need for a shared and accurate account of what happened and LayerZero working to 'harden security across every possible vector for applications'.