Kelp DAO Disputes LayerZero's Claims Regarding $290 Million Exploit

A recent cryptocurrency exploit has sparked a heated debate between Kelp DAO and LayerZero, with each party assigning blame to the other. The incident in question involved a $290 million loss due to a compromised verifier. Kelp DAO, a liquid restaking protocol, claims that the compromised entity was actually part of LayerZero's infrastructure, not a third-party verifier as LayerZero suggests. Furthermore, Kelp DAO argues that the setup which was exploited was based on LayerZero's default configuration, as outlined in their documentation and quickstart guides. This configuration, known as a 1/1 setup, relies on a single verifier to validate cross-chain transactions, leaving it vulnerable to attack if that verifier is compromised. Kelp DAO points out that 40% of protocols using LayerZero are currently using this same configuration. Security researchers have also questioned LayerZero's account of events, suggesting that the company may be deflecting responsibility for its own compromised infrastructure. The incident has led to a wider discussion about the security risks associated with cross-chain messaging protocols and the need for more robust verification processes.