Kelp DAO Disputes LayerZero's Account of $290 Million Exploit, Citing Default Settings as the Cause

A recent $290 million disaster has sparked a heated debate between Kelp DAO and LayerZero, with each side presenting a different account of the events that led to the massive loss. According to sources familiar with the matter, Kelp DAO is set to dispute LayerZero's post-mortem analysis of the incident, which allegedly blames Kelp for ignoring repeated warnings about its single-verifier setup. Kelp, a liquid restaking protocol, claims that the compromised verifier was actually part of LayerZero's own infrastructure, and that the setup in question was the default configuration recommended by LayerZero. The incident occurred when attackers drained 116,500 rsETH, worth approximately $290 million, from Kelp's LayerZero-powered bridge by poisoning the servers that LayerZero's verifier relied on to verify transactions. Kelp plans to argue that the compromised infrastructure was built and run by LayerZero, not Kelp, and that the '1/1 configuration' that LayerZero criticized was actually the default setup recommended in LayerZero's own quickstart guide and GitHub configuration. Security researchers have also questioned LayerZero's account of the incident, with some accusing the company of deflecting responsibility for its own compromised infrastructure. The debate has sparked a wider discussion about the security risks associated with cross-chain messaging protocols and the need for greater transparency and accountability in the industry.