Kelp DAO Disputes LayerZero's Claims Over $290 Million Exploit

A recent crypto controversy has sparked debate, with Kelp DAO set to challenge LayerZero's assessment of the $290 million exploit. According to a source familiar with the matter, Kelp plans to argue that the compromised verifier was part of LayerZero's own infrastructure and that the setup, which was criticized by LayerZero, was actually the default configuration provided by the cross-chain messaging firm. The exploit, which occurred on Saturday, saw attackers drain 116,500 rsETH, worth approximately $290 million, from Kelp's LayerZero-powered bridge by poisoning the servers that LayerZero's verifier relied on to check transactions. Kelp claims that the compromised DVN was LayerZero's own infrastructure, not a third-party verifier, and that the '1/1 configuration' used was the default setup recommended by LayerZero. The source also contested LayerZero's claim that Kelp ignored repeated warnings to move away from a single-verifier setup, stating that no specific recommendation was made to change the rsETH DVN configuration. Security researchers have also questioned LayerZero's framing of the incident, with one expert noting that LayerZero's reference setup ships with single-source verification defaults across every major chain. The controversy has led to a wider discussion about the security risks associated with cross-chain messaging and the importance of clear communication and configuration guidelines between protocols. As the situation continues to unfold, both Kelp DAO and LayerZero have released statements, with Kelp confirming that the 1-of-1 DVN setup reflects LayerZero's documented default configuration and LayerZero stating that it is working to 'harden security across every possible vector for applications'.