Kelp DAO Disputes LayerZero's Account of $290 Million Exploit, Claims Default Settings Were to Blame

A recent incident has sparked a heated debate in the crypto community, with Kelp DAO and LayerZero presenting differing accounts of a $290 million exploit. According to a source familiar with the matter, Kelp DAO plans to challenge LayerZero's claim that it was responsible for the breach due to its use of a single-verifier setup. Instead, Kelp DAO asserts that the compromised verifier was part of LayerZero's own infrastructure and that the setup was based on LayerZero's default configuration. The incident occurred when attackers drained 116,500 rsETH, worth approximately $290 million, from Kelp's LayerZero-powered bridge by compromising the servers that LayerZero's verifier relied on to verify transactions. Kelp DAO claims that the attackers compromised two of LayerZero's servers and then flooded the backup servers with junk traffic, forcing LayerZero's verifier onto the compromised servers. The source also contested LayerZero's assertion that Kelp DAO chose a 1-of-1 DVN setup despite warnings, stating that LayerZero's own quickstart guide and default GitHub configuration point to a 1/1 DVN setup, which is also used by 40% of protocols on LayerZero. Security researchers have also questioned LayerZero's account, with one expert noting that the reference setup ships with single-source verification defaults across every major chain and leaves a public endpoint exposed. In response to the incident, LayerZero has announced that it will no longer sign messages for any application running a single-verifier setup, forcing a protocol-wide migration. Kelp DAO has stated that it has operated on LayerZero infrastructure since January 2024 and maintained close communication with the LayerZero team, and that establishing a shared and accurate account of what happened is essential for making the necessary fixes.