Kelp DAO Disputes LayerZero's Claims Over $290 Million Disaster, Citing Default Settings as the Cause

A recent cryptocurrency exploit has sparked a heated debate between Kelp DAO and LayerZero, with each party attempting to shift the blame for the massive $290 million loss. The controversy centers around the use of a single-verifier setup, which Kelp DAO claims was the default configuration recommended by LayerZero. According to a source familiar with the matter, Kelp DAO plans to dispute LayerZero's claim that it ignored repeated warnings to move away from this setup. The incident occurred when attackers drained 116,500 rsETH, worth approximately $290 million, from Kelp's LayerZero-powered bridge by poisoning the servers that LayerZero's verifier relied on to check transactions. Kelp DAO asserts that the compromised verifier was part of LayerZero's own infrastructure, not a third-party entity, and that the setup in question was the default configuration provided by LayerZero. The company claims that LayerZero's post-mortem report unfairly blamed Kelp DAO for the exploit, despite the fact that the setup was the recommended default configuration. Security researchers have also questioned LayerZero's account of the incident, with some accusing the company of deflecting responsibility for its own compromised infrastructure. The dispute highlights the complexities and risks associated with cross-chain messaging and the need for clear communication and collaboration between parties involved. As the situation continues to unfold, both Kelp DAO and LayerZero have pledged to work towards improving security and preventing similar incidents in the future.