Kelp DAO Disputes LayerZero's Claims Regarding $290 Million Exploit
A recent incident has sparked a heated debate in the crypto community, with Kelp DAO and LayerZero at the center of the controversy. The issue began when Kelp DAO's bridge was exploited, resulting in a loss of approximately $290 million. LayerZero, the cross-chain messaging firm, released a post-mortem report that essentially blamed Kelp DAO for the incident, citing the protocol's use of a single-verifier setup as the primary cause. However, Kelp DAO has pushed back against these claims, arguing that the compromised verifier was actually part of LayerZero's own infrastructure and that the setup in question was the default configuration recommended by LayerZero. According to a source familiar with the matter, Kelp DAO plans to dispute LayerZero's claims, pointing out that the firm's own quickstart guide and default GitHub configuration recommend a 1/1 DVN setup, which is the same configuration used by Kelp DAO. The source also noted that 40% of protocols on LayerZero are currently using the same configuration. Security researchers have also weighed in on the issue, with some arguing that LayerZero is attempting to deflect responsibility for the incident. Yearn Finance core team developer Artem K, also known as @banteg on X, posted a technical review of LayerZero's public deployment code, noting that the reference setup ships with single-source verification defaults across every major chain. Chainlink community manager Zach Rynes accused LayerZero of throwing Kelp DAO under the bus for trusting a setup that LayerZero itself supported. In response to the incident, LayerZero has announced that it will no longer sign messages for any application running a single-verifier setup, forcing a protocol-wide migration. Kelp DAO has confirmed that it will work with LayerZero to establish a shared and accurate account of what happened and to make the necessary fixes to prevent similar incidents in the future.