Kelp DAO Disputes LayerZero's Claims Regarding $290 Million Disaster, Citing Default Settings as Culprit
A recent crypto controversy is unfolding, with Kelp DAO set to challenge LayerZero's account of the $290 million exploit that occurred on Sunday. According to a source familiar with the matter, Kelp plans to counter LayerZero's assertion that it was to blame for the incident due to its use of a single-verifier setup. Instead, Kelp claims that the compromised verifier was part of LayerZero's own infrastructure and that the setup in question was the default configuration provided by LayerZero. The incident involved the theft of 116,500 rsETH, worth approximately $290 million, from Kelp's LayerZero-powered bridge. The attackers reportedly poisoned the servers that LayerZero's verifier relied on to validate transactions, then flooded the backup servers with junk traffic to force LayerZero's verifier onto the compromised ones. Kelp argues that all of the infrastructure involved was built and run by LayerZero, not Kelp. The source also contested LayerZero's characterization of the '1/1 configuration' as a fringe choice made against guidance, pointing out that LayerZero's own quickstart guide and default GitHub configuration recommend a 1/1 DVN setup. Furthermore, 40% of protocols on LayerZero are currently using the same configuration. Security researchers have also questioned LayerZero's account, with one expert noting that the reference setup ships with single-source verification defaults across every major chain and leaves a public endpoint exposed. The incident has sparked a debate about responsibility, with some accusing LayerZero of deflecting blame and throwing Kelp under the bus for trusting a setup that LayerZero itself supported.