Kelp DAO Disputes LayerZero's Claims Regarding $290 Million Exploit

A recent $290 million disaster has sparked a heated debate between Kelp DAO and LayerZero, with each side pointing fingers at the other. According to a source familiar with the matter, Kelp DAO plans to challenge LayerZero's post-mortem analysis of the exploit, which suggests that Kelp ignored warnings about its single-verifier setup. Kelp, a liquid restaking protocol, claims that the compromised verifier was actually part of LayerZero's own infrastructure and that the setup was based on LayerZero's default configuration. The exploit occurred when attackers drained 116,500 rsETH, worth approximately $290 million, from Kelp's LayerZero-powered bridge by poisoning the servers that LayerZero's verifier relied on to check transactions. Kelp argues that the configuration used was not a fringe choice, but rather the default setup recommended by LayerZero. In fact, 40% of protocols on LayerZero are currently using the same configuration. Security researchers have also questioned LayerZero's framing of the incident, with some accusing the company of deflecting responsibility for its own compromised infrastructure. The incident has sparked a wider debate about the security risks associated with cross-chain messaging protocols and the need for greater transparency and accountability in the industry.