Kelp DAO Disputes LayerZero's Claims Over $290 Million Exploit

A recent crypto controversy has sparked a heated debate, with Kelp DAO set to challenge LayerZero's account of the $290 million exploit that occurred on Sunday. According to a source familiar with the matter, Kelp plans to argue that the compromised verifier was actually part of LayerZero's own infrastructure, and that the setup it was using was based on LayerZero's default configuration. This comes after LayerZero's post-mortem of the incident, which essentially blamed Kelp for ignoring warnings to move away from a single-verifier setup. Kelp, a liquid restaking protocol, takes user-deposited ether and routes it through a yield-generating system called EigenLayer, issuing a receipt token called rsETH in exchange. LayerZero is the cross-chain messaging infrastructure that moves rsETH between blockchains, using entities called decentralized verifier networks (DVNs) to verify the validity of cross-chain transfers. On Saturday, attackers drained 116,500 rsETH, worth around $290 million, from Kelp's LayerZero-powered bridge by poisoning the servers that LayerZero's verifier relied on to check transactions. The source claims that the DVN that was compromised was LayerZero's own infrastructure, not a third-party verifier, and that the attackers compromised two of LayerZero's own servers that check the legitimacy of cross-chain transactions, then flooded the backup servers with junk traffic to force LayerZero's verifier onto the compromised ones. Kelp is planning to argue that the '1/1 configuration' that was used, which means only a single validator must sign off on a cross-chain message for the bridge to act on it, was actually LayerZero's default setup. The source also contested LayerZero's claim that Kelp chose this configuration despite expressing recommendations to configure multi-DVN redundancy, stating that LayerZero's own quickstart guide and default GitHub configuration point to a 1/1 DVN setup, and that 40% of protocols on LayerZero are currently using the same configuration. Security researchers have also questioned LayerZero's account of the incident, with one researcher stating that LayerZero's reference setup ships with single-source verification defaults across every major chain, and that the deployment leaves a public endpoint exposed that leaks the list of configured servers to anyone who queries it. The incident has sparked a wider debate about the security of cross-chain messaging infrastructure, with some accusing LayerZero of 'deflecting responsibility' for its own compromised infrastructure. Kelp DAO has confirmed that it will no longer use the single-verifier setup, and LayerZero has announced that it will no longer sign messages for any application running a single-verifier setup, forcing a protocol-wide migration.