Kelp DAO Disputes LayerZero's Claims on $290 Million Disaster, Citing Default Settings as the Cause
A recent crypto controversy has sparked debate, with Kelp DAO set to challenge LayerZero's post-mortem analysis of the $290 million exploit that occurred on Sunday. According to a source familiar with the matter, Kelp plans to dispute LayerZero's claim that it ignored repeated warnings to move away from a single-verifier setup. The dispute centers around the cross-chain messaging firm's claim that Kelp's configuration was to blame for the massive loss. However, Kelp claims that the compromised verifier was part of LayerZero's own infrastructure and that the setup was based on LayerZero's default onboarding configuration. The incident has sparked a wider debate about the security of cross-chain messaging infrastructure and the role of default settings in facilitating such exploits. Security researchers have also weighed in, criticizing LayerZero's attempts to deflect responsibility and arguing that the company's default settings and documentation may have contributed to the vulnerability. As the situation continues to unfold, both Kelp DAO and LayerZero have issued statements, with Kelp confirming that it used LayerZero's default configuration and LayerZero announcing plans to 'harden security across every possible vector for applications'.