Kelp DAO disputes LayerZero's claims, citing default settings as the cause of $290 million loss

A recent cryptocurrency incident has sparked a heated debate, with Kelp DAO and LayerZero pointing fingers at each other. Kelp DAO is contesting LayerZero's post-mortem analysis of the $290 million exploit, which occurred on Sunday. According to a source familiar with the matter, Kelp DAO plans to argue that the compromised verifier was part of LayerZero's own infrastructure and that the setup was based on LayerZero's default onboarding configuration. The incident involved the draining of 116,500 rsETH, worth approximately $290 million, from Kelp's LayerZero-powered bridge. Kelp DAO claims that the attack was a sophisticated state-sponsored attack that compromised two of LayerZero's servers, which were then used to flood backup servers with junk traffic. The source also contested LayerZero's claim that Kelp DAO chose a 1-of-1 DVN setup despite recommendations to configure multi-DVN redundancy, stating that LayerZero's own quickstart guide and default GitHub configuration point to a 1/1 DVN setup. Security researchers have also questioned LayerZero's framing of the incident, with one researcher noting that LayerZero's reference setup ships with single-source verification defaults across every major chain. The incident has sparked a wider debate about the security of cryptocurrency infrastructure and the need for greater transparency and accountability.