Kelp DAO Shifts Blame to LayerZero for $290 Million Disaster, Citing Default Settings

A recent crypto incident has sparked a heated debate, with Kelp DAO set to dispute LayerZero's account of the $290 million exploit that occurred on Sunday. According to a source familiar with the matter, Kelp plans to argue that the cross-chain messaging firm's claim that it ignored warnings to move away from a single-verifier setup is inaccurate. The liquid restaking protocol, which takes user-deposited ether and issues a receipt token called rsETH, claims that the compromised verifier was actually part of LayerZero's own infrastructure, not a third-party verifier. The attack, which drained 116,500 rsETH worth about $290 million, was made possible by compromising two of LayerZero's servers that check the legitimacy of cross-chain transactions. Kelp argues that the setup in question, which LayerZero has framed as a fringe choice made against guidance, was actually the default configuration provided by LayerZero. The source claims that LayerZero's own quickstart guide and default GitHub configuration point to a 1/1 DVN setup, which is the same configuration used by 40% of protocols on LayerZero. Security researchers have also questioned LayerZero's account, with one researcher noting that the reference setup ships with single-source verification defaults across every major chain. The incident has sparked a wider debate about the security of cross-chain messaging infrastructure and the need for greater transparency and accountability in the crypto industry.