Kelp DAO Disputes LayerZero's Account of $290 Million Exploit, Claims Default Settings Were to Blame

A recent $290 million crypto exploit has sparked a heated debate between Kelp DAO and LayerZero, with each party blaming the other for the security breach. According to a source familiar with the matter, Kelp DAO plans to dispute LayerZero's claim that it ignored warnings about its single-verifier setup. Instead, Kelp DAO claims that the compromised verifier was part of LayerZero's own infrastructure and that the setup was based on LayerZero's default configuration. The incident occurred when attackers drained 116,500 rsETH, worth approximately $290 million, from Kelp's LayerZero-powered bridge by poisoning the servers that LayerZero's verifier relied on to check transactions. Kelp DAO argues that the infrastructure was built and run by LayerZero, not Kelp, and that the '1/1 configuration' used was actually LayerZero's recommended default setup. Security researchers have also questioned LayerZero's account of the incident, with some accusing the company of deflecting responsibility. The dispute highlights the complexities of cross-chain messaging infrastructure and the need for clear communication and shared responsibility between protocols.