Kelp DAO Disputes LayerZero's Account of $290 Million Disaster, Citing Default Settings
A recent crypto controversy has drawn comparisons to a popular Spiderman meme, with Kelp DAO and LayerZero pointing fingers at each other over a $290 million disaster. According to a source familiar with the matter, Kelp DAO is preparing to challenge LayerZero's post-mortem report, which blamed Kelp for ignoring warnings about its single-verifier setup. Kelp plans to argue that the compromised verifier was actually LayerZero's own infrastructure and that the setup in question was LayerZero's default configuration. The incident occurred when attackers drained 116,500 rsETH, worth approximately $290 million, from Kelp's LayerZero-powered bridge by poisoning LayerZero's verifier servers. Kelp claims that LayerZero's own servers were compromised, not a third-party verifier, and that the company's quickstart guide and default GitHub configuration recommend a 1/1 DVN setup, which 40% of protocols on LayerZero currently use. Security researchers have also questioned LayerZero's account, with one expert noting that the company's reference setup ships with single-source verification defaults and leaves a public endpoint exposed. The controversy has sparked a wider debate about responsibility and security in the crypto industry, with some accusing LayerZero of deflecting blame and others calling for greater transparency and accountability.