Kelp DAO Blames LayerZero for $292 Million Bridge Hack
- Kelp DAO claims LayerZero personnel approved a vulnerable 1-of-1 verifier setup, leading to a $292 million exploit.
- The exploit drained approximately 116,500 rsETH from Kelp’s bridge, with additional forged transactions exceeding $100 million.
- LayerZero’s postmortem stated that the protocol “functioned exactly as intended,” despite Kelp’s claims of oversight.
- CoinGecko reported that nearly half (47%) of active LayerZero OApp contracts utilized the same risky configuration.
- Kelp plans to migrate rsETH to Chainlink‘s Cross-Chain Interoperability Protocol following the incident.
The conflict centers around security practices and oversight between Kelp DAO and LayerZero, particularly regarding the approval of a single-verifier model that was exploited by attackers linked to North Korea’s Lazarus Group.
With over $4.5 billion in market value exposed due to similar setups, this incident raises significant concerns about security protocols in decentralized applications.(Source)