Kelp DAO Shifts Blame to LayerZero for $290 Million Disaster, Citing Default Settings

A recent cryptocurrency exploit has sparked a heated debate, with Kelp DAO set to dispute LayerZero's claim that it was responsible for the $290 million disaster. According to a source familiar with the matter, Kelp DAO plans to argue that the compromised verifier was actually part of LayerZero's own infrastructure and that the setup it was using was LayerZero's default configuration. The incident occurred when attackers drained 116,500 rsETH, worth approximately $290 million, from Kelp's LayerZero-powered bridge by poisoning the servers that LayerZero's verifier relied on to check transactions. Kelp DAO claims that the infrastructure that was compromised was built and run by LayerZero, not by Kelp. The source also contested LayerZero's framing of the '1/1 configuration' as a fringe choice made against guidance, stating that LayerZero's own quickstart guide and default GitHub configuration point to a 1/1 DVN setup, which is also used by 40% of protocols on LayerZero. Security researchers have also questioned LayerZero's isolated framing, which pinned the blame on Kelp, with some accusing LayerZero of deflecting responsibility for its own compromised infrastructure. The incident has sparked a wider debate about the security of cryptocurrency protocols and the need for greater transparency and accountability.