Kelp DAO Shifts Blame to LayerZero for $290 Million Disaster, Citing Default Settings

A recent cryptocurrency exploit has sparked a heated debate, with Kelp DAO planning to dispute LayerZero's claim that it ignored warnings about its single-verifier setup. The incident involved a $290 million loss due to a sophisticated state-sponsored attack on LayerZero's infrastructure. According to a source familiar with the matter, Kelp DAO will argue that the compromised verifier was part of LayerZero's own infrastructure, not a third-party verifier, and that the setup was based on LayerZero's default configuration. The attack exploited a single-verifier setup, which allowed the attackers to drain 116,500 rsETH, worth about $290 million, from Kelp's LayerZero-powered bridge. Kelp DAO claims that it relied on LayerZero's documentation and defaults when making configuration decisions and that 40% of protocols on LayerZero are currently using the same 1/1 configuration. Security researchers have also questioned LayerZero's framing of the incident, with some accusing the company of deflecting responsibility. The incident has led to a protocol-wide migration, with LayerZero announcing that it will no longer sign messages for any application running a single-verifier setup.