LayerZero says it made an error in how it handled security for high-value transfers tied to its Kelp incident, following earlier explanations that suggested a developer configuration problem. In its updated account, the company acknowledges that it made the decision to allow its own verifier to secure high-value transfers under a setup that later proved vulnerable. LayerZero also frames the change as an ownership of responsibility rather than an external misconfiguration.

In a public apology, the company addresses how it previously responded to the Kelp DAO exploit. It also confirms and expands on details of the incident response, including disclosures that were not previously reported. Separately, LayerZero states there was an additional incident involving a multisig signer who used their production hardware wallet to carry out a personal trade.

Across the coverage, LayerZero’s statements center on taking responsibility for the technical and process decisions connected to the exploit and on providing further transparency about its internal actions related to the incident and its aftermath.