Kelp DAO Disputes LayerZero's Claims Over $290 Million Loss

A recent incident involving a $290 million loss has sparked a heated debate between Kelp DAO and LayerZero. Kelp DAO is pushing back against LayerZero's claims that it was responsible for the loss due to its use of a single-verifier setup. According to Kelp DAO, the compromised verifier was actually part of LayerZero's own infrastructure, and the setup in question was the default configuration provided by LayerZero. This configuration, known as a 1/1 setup, means that only one validator is required to sign off on a cross-chain message for the bridge to act on it. Kelp DAO claims that it relied on LayerZero's documentation and guidance when making configuration decisions and that the 1/1 setup was the recommended default. Security researchers have also questioned LayerZero's claims, with one expert pointing out that LayerZero's reference setup ships with single-source verification defaults across every major chain. The incident has led to a wider discussion about the security risks associated with cross-chain messaging and the need for more robust verification processes. In response to the incident, LayerZero has announced that it will no longer sign messages for any application running a single-verifier setup, forcing a protocol-wide migration to more secure configurations.