Kelp DAO Disputes LayerZero's Claims Over $290 Million Exploit

A recent cryptocurrency exploit has sparked a heated debate between Kelp DAO and LayerZero. The incident, which resulted in a $290 million loss, has been attributed to a single-verifier setup by LayerZero. However, Kelp DAO claims that this setup was actually the default configuration provided by LayerZero. According to a source familiar with the matter, Kelp DAO plans to dispute LayerZero's claims, stating that the compromised verifier was part of LayerZero's own infrastructure. The incident has raised questions about the security of cross-chain messaging protocols and the responsibility of infrastructure providers. Kelp DAO, a liquid restaking protocol, had been using LayerZero's infrastructure to move its receipt token, rsETH, between blockchains. The attack, which occurred on Saturday, drained 116,500 rsETH, worth approximately $290 million, from Kelp's LayerZero-powered bridge. Kelp DAO alleges that the attack was made possible by a 'sophisticated state-sponsored attack' that compromised two of LayerZero's own servers. The source claims that LayerZero's post-mortem of the incident misrepresents the facts, as the 1/1 configuration used by Kelp DAO was actually the default setup recommended by LayerZero. Furthermore, the source notes that 40% of protocols on LayerZero are currently using the same configuration. Security researchers have also questioned LayerZero's account of the incident, with some accusing the company of 'deflecting responsibility' for its own compromised infrastructure. The incident has led to a wider discussion about the security risks associated with cross-chain messaging protocols and the need for greater transparency and accountability in the industry.