Kelp DAO Disputes LayerZero's Account of $290 Million Exploit, Citing 'Default' Settings
A recent cryptocurrency exploit has sparked a heated debate between Kelp DAO and LayerZero, with each party assigning blame for the $290 million disaster. The incident occurred when attackers drained 116,500 rsETH, worth approximately $290 million, from Kelp's LayerZero-powered bridge. Kelp DAO, a liquid restaking protocol, claims that the compromised decentralized verifier network (DVN) was part of LayerZero's own infrastructure, not a third-party verifier. According to Kelp, the setup that was compromised was based on LayerZero's default configuration, which is also used by 40% of protocols on the platform. The dispute centers around the '1/1 configuration', which means that only a single validator must sign off on a cross-chain message for the bridge to act on it, leaving the system vulnerable to a single point of failure. Kelp argues that this configuration was recommended by LayerZero's own quickstart guide and default GitHub configuration. Security researchers have also questioned LayerZero's account of the incident, with some accusing the company of 'deflecting responsibility' for its own compromised infrastructure. The incident has led to a protocol-wide migration, with LayerZero announcing that it will no longer sign messages for any application running a single-verifier setup. As the situation continues to unfold, both parties are working to establish a shared understanding of what happened and to implement fixes to prevent similar incidents in the future.