BlockBeats News, May 6th – Regarding the recent allegations made by KelpDAO against LayerZero in the rsETH security incident, LayerZero CEO Bryan Pellegrino publicly responded today on social media and provided key technical details.
Pellegrino stated that the facts were not as claimed by Kelp. According to the immutable on-chain records, on April 1, 2024, KelpDAO voluntarily switched the cross-chain configuration of rsETH from the default "multi DVN" setting to a manually configured "1/1 single DVN" mode. He specifically pointed out that LayerZero's official documentation had prominently warned against using this 1/1 configuration in a production environment. He further added that the LayerZero team had consistently recommended KelpDAO to use the more secure "2/3 multisig scheme" when providing professional advice in the past, a recommendation that Kelp did not heed.
Pellegrino also revealed a key data point indicating that during the operation of this 1/1 configuration, close to 100% of the associated cross-chain transaction volume originated from rsETH itself. Pellegrino mentioned that LayerZero is currently awaiting the final review report from an external security firm, after which a comprehensive event analysis will be released. He suggested that the fundamental reason behind this incident was the project's disregard for basic security guidelines.
