Kelp DAO Disputes LayerZero's Claims on $290 Million Disaster, Citing Default Settings as the Cause

A recent cryptocurrency exploit has sparked a heated debate between Kelp DAO and LayerZero, with Kelp planning to contest LayerZero's post-exploit analysis. The incident in question resulted in the loss of approximately $290 million. According to a source familiar with the matter, Kelp will argue that the compromised verifier was actually part of LayerZero's infrastructure, and that the setup that was criticized was, in fact, the default configuration recommended by LayerZero. This setup, known as a '1/1 configuration,' relies on a single validator to sign off on cross-chain messages, leaving the system vulnerable to a single point of failure. Kelp claims that LayerZero's own quickstart guide and default GitHub configuration point to this setup, and that 40% of protocols on LayerZero are currently using it. The incident has sparked a wider discussion about the security of cryptocurrency protocols and the need for greater transparency and accountability. Security researchers have also weighed in, with some arguing that LayerZero is attempting to deflect responsibility for the exploit. The situation is ongoing, with both Kelp DAO and LayerZero issuing statements and updates on their respective actions and plans to prevent similar incidents in the future.