Kelp DAO Disputes LayerZero's Claims Over $290 Million Exploit
A recent $290 million disaster has sparked a heated debate between Kelp DAO and LayerZero, with each side pointing fingers at the other. Kelp DAO is pushing back against LayerZero's claims that it ignored warnings about its single-verifier setup, which was allegedly to blame for the massive exploit. According to a source familiar with the matter, Kelp plans to argue that the compromised verifier was actually part of LayerZero's own infrastructure and that the setup was based on LayerZero's default onboarding configuration. The incident occurred when attackers drained 116,500 rsETH, worth around $290 million, from Kelp's LayerZero-powered bridge by poisoning the servers that LayerZero's verifier relied on to check transactions. Kelp claims that the attack was a sophisticated state-sponsored attack that compromised two of LayerZero's own servers, which were then used to flood the backup servers with junk traffic and force LayerZero's verifier onto the compromised ones. The source contested LayerZero's framing of the '1/1 configuration' as a fringe choice made against guidance, arguing that LayerZero's own quickstart guide and default GitHub configuration point to a 1/1 DVN setup. In fact, 40% of protocols on LayerZero are currently using the same configuration. Kelp's core restaking contracts were not touched, and the exploit was isolated to the bridge layer. The emergency pause, 46 minutes after the drain, blocked two follow-up attempts that would have released an additional ~$200 million in rsETH. Security researchers are also questioning LayerZero's claims, with one researcher noting that LayerZero's reference setup ships with single-source verification defaults across every major chain. Chainlink community manager Zach Rynes accused LayerZero of 'deflecting responsibility' for its own compromised infrastructure and throwing Kelp under the bus for trusting a setup LayerZero itself supported. As the debate continues, Kelp DAO has confirmed that it will no longer use a single-verifier setup and will instead migrate to a multi-verifier configuration.