@LayerZero_Core KelpDAO: -25% responsibility — placed excessive trust in LayerZero and used LayerZero’s single in-house DVN.
Aave: -15% responsibility — identified the issue but failed to remediate it; risk controls were inadequate, and exposure to rsETH became too large too quickly.
@LayerZero_Core From a purely third-party perspective, the allocation of responsibility for this incident is:
LayerZero: -60% responsibility — allowed a single DVN configuration; its in-house DVN was compromised.