Kelp DAO Disputes LayerZero's Account of $290 Million Exploit, Citing Default Settings as Culprit
A recent crypto incident has sparked a heated debate, with Kelp DAO set to challenge LayerZero's post-mortem analysis of the $290 million exploit that occurred on Sunday. According to a source familiar with the matter, Kelp plans to argue that the cross-chain messaging firm's claim that it ignored warnings to move away from a single-verifier setup is inaccurate. The incident involved the compromise of LayerZero's own servers, which were used to verify cross-chain transactions, and the subsequent draining of 116,500 rsETH, worth approximately $290 million, from Kelp's LayerZero-powered bridge. Kelp contends that the compromised verifier was part of LayerZero's infrastructure, not a third-party verifier, and that the setup was based on LayerZero's default configuration. The source also claims that LayerZero's post-mortem misrepresents the '1/1 configuration' as a fringe choice made against guidance, when in fact it is the default setup recommended by LayerZero. Security researchers have also questioned LayerZero's account, with one expert noting that the company's reference setup ships with single-source verification defaults across every major chain. The incident has sparked a wider debate about the security of cross-chain messaging infrastructure and the need for greater transparency and accountability in the crypto industry.