Kelp DAO Disputes LayerZero's Claims Over $290 Million Disaster, Alleging Default Settings Were to Blame

A recent incident involving a $290 million disaster has sparked a heated debate between Kelp DAO and LayerZero. According to Kelp DAO, the compromised verifier was actually part of LayerZero's own infrastructure, and the setup that was faulted for the disaster was based on LayerZero's default configuration. This claim disputes LayerZero's post-mortem, which essentially blamed Kelp DAO for ignoring repeated warnings to move away from a single-verifier setup. Kelp DAO plans to push back against these claims, citing that the configuration used was based on LayerZero's own quickstart guide and default GitHub configuration. The incident has raised questions about the security of cross-chain messaging infrastructure and the responsibility of protocols in ensuring the safety of user funds. Security researchers have also weighed in, with some accusing LayerZero of deflecting responsibility and blaming Kelp DAO for trusting a setup that LayerZero itself supported.