Kelp DAO Disputes LayerZero's Claims Regarding $290 Million Exploit
A recent crypto controversy is unfolding, with Kelp DAO set to challenge LayerZero's account of the $290 million exploit that occurred on Sunday. According to a source familiar with the matter, Kelp DAO plans to dispute LayerZero's claim that it ignored warnings to move away from a single-verifier setup. Kelp is a liquid restaking protocol that utilizes user-deposited ether, routes it through a yield-generating system called EigenLayer, and issues a receipt token called rsETH in exchange. LayerZero provides the cross-chain messaging infrastructure that facilitates the transfer of rsETH between blockchains, relying on entities known as decentralized verifier networks (DVNs) to verify the validity of cross-chain transfers. On Saturday, attackers drained approximately 116,500 rsETH, worth around $290 million, from Kelp's LayerZero-powered bridge by compromising the servers that LayerZero's verifier relied on to verify transactions. Kelp claims that the compromised DVN was part of LayerZero's own infrastructure, not a third-party verifier, and that the setup was based on LayerZero's default configuration. The source contests LayerZero's framing of the '1/1 configuration' as a fringe choice made against guidance, stating that LayerZero's own quickstart guide and default GitHub configuration point to a 1/1 DVN setup, which 40% of protocols on LayerZero are currently using. Security researchers are also skeptical of LayerZero's claims, with one expert noting that LayerZero's reference setup ships with single-source verification defaults across every major chain, including Ethereum, BSC, Polygon, Arbitrum, and Optimism. The incident has sparked a heated debate, with some accusing LayerZero of deflecting responsibility for its own compromised infrastructure and throwing Kelp under the bus for trusting a setup that LayerZero itself supported. As the situation continues to unfold, both Kelp DAO and LayerZero have released statements, with Kelp confirming that the 1-of-1 DVN setup reflects LayerZero's documented default configuration and LayerZero announcing plans to 'harden security across every possible vector for applications.'