Kelp DAO Counters LayerZero's Claims, Alleging Default Settings Caused $290 Million Disaster

A recent $290 million exploit has sparked a heated debate between Kelp DAO and LayerZero, with Kelp set to challenge LayerZero's account of the incident. According to a source familiar with the matter, Kelp plans to argue that the compromised verifier was actually part of LayerZero's own infrastructure, rather than a third-party verifier. The dispute centers around the use of a single-verifier setup, which Kelp claims was based on LayerZero's default configuration. LayerZero's post-mortem had blamed Kelp for ignoring warnings to move away from this setup, but Kelp disputes this, stating that the configuration was recommended by LayerZero's own documentation and team. The incident has raised questions about the security of cross-chain messaging infrastructure and the responsibility of providers like LayerZero. Security researchers have also weighed in, with some accusing LayerZero of deflecting blame and failing to acknowledge its own role in the exploit. As the situation continues to unfold, both Kelp DAO and LayerZero have released statements, with Kelp emphasizing the need for a shared understanding of what happened and LayerZero committing to improve security across its applications.