Kelp DAO Claims LayerZero's Default Settings Were Responsible for $290 Million Disaster
A recent incident has sparked a heated debate in the crypto community, with Kelp DAO set to dispute LayerZero's account of the $290 million exploit that occurred on Sunday. According to a source familiar with the matter, Kelp plans to argue that the compromised verifier was part of LayerZero's own infrastructure, not a third-party verifier, and that the setup that was criticized was actually based on LayerZero's default configuration. The incident involved the theft of 116,500 rsETH, worth approximately $290 million, from Kelp's LayerZero-powered bridge. Kelp claims that the attackers compromised two of LayerZero's own servers, which were used to verify cross-chain transactions, and then flooded the backup servers with junk traffic to force LayerZero's verifier onto the compromised ones. The source also contested LayerZero's claim that Kelp chose a 1-of-1 DVN setup despite recommendations to configure multi-DVN redundancy, stating that LayerZero's own quickstart guide and default GitHub configuration point to a 1/1 DVN setup, which is also used by 40% of protocols on LayerZero. Security researchers have also questioned LayerZero's framing of the incident, with one researcher noting that LayerZero's reference setup ships with single-source verification defaults across every major chain. The incident has led to a protocol-wide migration, with LayerZero announcing that it will no longer sign messages for any application running a single-verifier setup.