Kelp DAO Disputes LayerZero's Claims Over $290 Million Disaster, Citing Default Settings
A recent incident involving a $290 million exploit has sparked a heated debate between Kelp DAO and LayerZero. According to sources, Kelp DAO plans to dispute LayerZero's claims that it ignored warnings about its single-verifier setup. Instead, Kelp DAO argues that the compromised verifier was part of LayerZero's own infrastructure and that the setup was based on LayerZero's default onboarding configuration. The incident occurred when attackers drained 116,500 rsETH, worth approximately $290 million, from Kelp's LayerZero-powered bridge by poisoning the servers that LayerZero's verifier relied on to check transactions. Kelp DAO claims that the infrastructure was built and run by LayerZero, not Kelp, and that the default configuration was used. Security researchers have also questioned LayerZero's claims, with one expert noting that LayerZero's reference setup ships with single-source verification defaults across every major chain. The incident has led to a wider discussion about the security risks associated with cross-chain messaging and the need for greater transparency and accountability in the industry.