Kelp DAO Disputes LayerZero's Claims Regarding $290 Million Incident

A recent incident involving a $290 million exploit has sparked a dispute between Kelp DAO and LayerZero, with Kelp set to challenge LayerZero's claims that it was responsible for the incident due to its use of a single-verifier setup. According to a source familiar with the matter, Kelp plans to argue that the compromised verifier was actually part of LayerZero's own infrastructure, and that the setup in question was LayerZero's default configuration. The incident occurred when attackers drained 116,500 rsETH, worth approximately $290 million, from Kelp's LayerZero-powered bridge by poisoning the servers that LayerZero's verifier relied on to check transactions. Kelp claims that the infrastructure in question was built and run by LayerZero, and that it had been using LayerZero's default configuration, which is also used by 40% of protocols on the platform. The company argues that LayerZero's own quickstart guide and default GitHub configuration point to a 1/1 DVN setup, and that it had been in direct communication with LayerZero since July 2024, with no specific recommendations made to change the rsETH DVN configuration. Security researchers have also questioned LayerZero's account of the incident, with some accusing the company of deflecting responsibility for its own compromised infrastructure. In response to the incident, LayerZero has announced that it will no longer sign messages for any application running a single-verifier setup, forcing a protocol-wide migration. Kelp DAO has confirmed that it is working with LayerZero to establish a shared understanding of what happened and to make the necessary fixes.