Kelp DAO Disputes LayerZero's Account of $290 Million Exploit, Citing Default Settings

A recent crypto controversy has sparked a heated debate, with Kelp DAO set to challenge LayerZero's post-exploit analysis, which placed blame on Kelp for the $290 million disaster. According to a source familiar with the matter, Kelp plans to argue that the compromised verifier was actually LayerZero's own infrastructure, and that the setup in question was the default configuration provided by LayerZero. This comes after attackers drained 116,500 rsETH, worth approximately $290 million, from Kelp's LayerZero-powered bridge by compromising the servers that LayerZero's verifier relied on to check transactions. Kelp claims that the infrastructure in question was built and run by LayerZero, not Kelp, and that LayerZero's own quickstart guide and default GitHub configuration point to a 1/1 DVN setup, which 40% of protocols on LayerZero are currently using. Security researchers have also questioned LayerZero's framing of the incident, with some alleging that the company is deflecting responsibility for its own compromised infrastructure. The incident has sparked a wider conversation about the security risks associated with cross-chain messaging and the need for greater transparency and accountability in the crypto space.