Kelp DAO Disputes LayerZero's Claims Over $290 Million Disaster, Citing Default Settings as the Cause
A recent crypto controversy has erupted, with Kelp DAO set to challenge LayerZero's post-mortem analysis of the $290 million exploit that occurred on Sunday. According to a source familiar with the matter, Kelp DAO plans to argue that it was not at fault for the attack, but rather that the compromised verifier was part of LayerZero's own infrastructure. The incident involved the drainage of 116,500 rsETH, worth approximately $290 million, from Kelp's LayerZero-powered bridge. Kelp DAO claims that the setup that was compromised was based on LayerZero's default onboarding configuration, which it had been using since January 2024. The source also stated that LayerZero's own quickstart guide and default GitHub configuration point to a 1/1 DVN setup, which is the same configuration that Kelp DAO was using. Security researchers have also questioned LayerZero's claims, with one researcher noting that the reference setup ships with single-source verification defaults across every major chain. The controversy has sparked a debate about the security of cross-chain messaging infrastructure and the responsibility of protocols to ensure the safety of user funds.