Kelp DAO Disputes LayerZero's Account of $290 Million Exploit

A recent cryptocurrency exploit has sparked a heated debate between Kelp DAO and LayerZero, with each side blaming the other for the $290 million disaster. The incident occurred when attackers drained 116,500 rsETH, worth about $290 million, from Kelp's LayerZero-powered bridge by poisoning the servers that LayerZero's verifier relied on to check transactions. Kelp DAO is now set to dispute LayerZero's post-mortem of the incident, which essentially blames Kelp for ignoring repeated warnings to move away from a single-verifier setup. According to a source familiar with the matter, Kelp plans to argue that the compromised verifier was actually LayerZero's own infrastructure, and that the setup it was faulted for running was LayerZero's onboarding default. This claim is supported by the fact that LayerZero's own quickstart guide and default GitHub configuration point to a 1/1 DVN setup, which is the same configuration used by Kelp. Furthermore, 40% of protocols on LayerZero are currently using the same configuration, which suggests that it is a common and accepted setup. Security researchers have also come to Kelp's defense, with one researcher noting that LayerZero's reference setup ships with single-source verification defaults across every major chain, including Ethereum, BSC, Polygon, Arbitrum, and Optimism. The researcher also pointed out that the deployment leaves a public endpoint exposed that leaks the list of configured servers to anyone who queries it. As the situation continues to unfold, it remains to be seen how the incident will affect the relationship between Kelp DAO and LayerZero, as well as the broader cryptocurrency community. One thing is certain, however: the incident has highlighted the importance of robust security measures and the need for clear communication and collaboration between different stakeholders in the cryptocurrency space.