Kelp DAO Disputes LayerZero's Claims Regarding $290 Million Disaster, Citing Default Settings as the Cause

A recent cryptocurrency incident has sparked a heated debate, with Kelp DAO set to dispute LayerZero's post-mortem analysis of the $290 million exploit that occurred on Sunday. According to a source familiar with the matter, Kelp plans to argue that it was LayerZero's own infrastructure and default settings that led to the disaster, rather than Kelp's alleged failure to heed warnings about its single-verifier setup. The incident involved the theft of 116,500 rsETH, worth approximately $290 million, from Kelp's LayerZero-powered bridge. Kelp claims that the compromised decentralized verifier network (DVN) was part of LayerZero's own infrastructure, not a third-party verifier, and that the setup that was faulted was actually LayerZero's default configuration. The source also contested LayerZero's claim that Kelp chose a 1-of-1 DVN setup despite recommendations to configure multi-DVN redundancy, stating that LayerZero's own quickstart guide and default GitHub configuration point to a 1/1 DVN setup, which is also used by 40% of protocols on LayerZero. Security researchers have also questioned LayerZero's framing of the incident, with one researcher noting that LayerZero's reference setup ships with single-source verification defaults across every major chain. The incident has led to a wider debate about the security of cryptocurrency protocols and the need for greater transparency and accountability.