Kelp DAO Disputes LayerZero's Account of $290 Million Exploit

A recent $290 million exploit has sparked a heated debate between Kelp DAO and LayerZero, with each party blaming the other for the disaster. According to a source familiar with the matter, Kelp DAO plans to dispute LayerZero's claim that it ignored repeated warnings to move away from a single-verifier setup. Instead, Kelp DAO argues that the compromised verifier was part of LayerZero's own infrastructure and that the setup it was faulted for running was actually LayerZero's default configuration. The incident occurred when attackers drained 116,500 rsETH, worth about $290 million, from Kelp's LayerZero-powered bridge by poisoning the servers that LayerZero's verifier relied on to check transactions. Kelp DAO claims that the infrastructure was built and run by LayerZero, not Kelp, and that LayerZero's own quickstart guide and default GitHub configuration point to a 1/1 DVN setup, which 40% of protocols on LayerZero are currently using. Security researchers have also questioned LayerZero's account of the incident, with some accusing the company of deflecting responsibility for its own compromised infrastructure. The dispute highlights the need for greater clarity and accountability in the crypto space, particularly when it comes to cross-chain messaging infrastructure and the potential risks associated with it.