Kelp DAO Disputes LayerZero's Account of $290 Million Exploit, Citing Default Settings as Culprit
A recent crypto controversy has erupted, with Kelp DAO pushing back against LayerZero's post-mortem analysis of the $290 million exploit. According to a source familiar with the matter, Kelp plans to argue that the compromised verifier was actually part of LayerZero's own infrastructure, and that the setup in question was the default configuration provided by LayerZero. This configuration, known as a 1/1 setup, relies on a single validator to sign off on cross-chain messages, leaving the system vulnerable to a single point of failure. Kelp claims that this setup was not only recommended by LayerZero but also widely used by other protocols on the platform. Security researchers have also questioned LayerZero's account, with one expert noting that the company's reference setup ships with single-source verification defaults and leaves a public endpoint exposed. As the debate continues, both Kelp DAO and LayerZero have released statements, with Kelp confirming that it used the default configuration and LayerZero announcing plans to harden security across all possible vectors.