Kelp DAO Disputes LayerZero's Account of $290 Million Exploit, Blames Default Settings

A recent exploit resulting in the loss of $290 million has sparked a heated debate between Kelp DAO and LayerZero, with each party blaming the other for the security breach. Kelp DAO, a liquid restaking protocol, is contesting LayerZero's post-mortem analysis, which attributed the exploit to Kelp's use of a single-verifier setup despite warnings to adopt a more secure configuration. According to a source familiar with the matter, Kelp plans to argue that the compromised verifier was actually part of LayerZero's own infrastructure and that the setup was based on LayerZero's default configuration. The incident occurred when attackers poisoned the servers used by LayerZero's verifier to check transactions, allowing them to drain 116,500 rsETH, worth approximately $290 million, from Kelp's LayerZero-powered bridge. Kelp claims that it relied on LayerZero's documentation and guidance when configuring its setup and that the 1/1 configuration used was the default setting recommended by LayerZero. Security researchers have also questioned LayerZero's account of the incident, with some accusing the company of deflecting responsibility for its own compromised infrastructure. The dispute highlights the need for clear communication and shared responsibility between protocols and infrastructure providers to prevent similar incidents in the future.