Kelp DAO Counters LayerZero's Claims, Asserts 'Default' Settings Led to $290 Million Loss
A recent $290 million crypto exploit has sparked a heated debate between Kelp DAO and LayerZero, with each party pointing fingers at the other. The controversy centers around the massive loss incurred when attackers drained 116,500 rsETH from Kelp's LayerZero-powered bridge, worth approximately $290 million. Kelp DAO, a liquid restaking protocol, claims the compromised verifier was not a third-party entity, but rather LayerZero's own infrastructure. Furthermore, Kelp asserts that the setup, which has been criticized for having a single-verifier configuration, was actually LayerZero's default setting. According to a source familiar with the matter, LayerZero's own quickstart guide and default GitHub configuration recommend a 1/1 DVN setup, which is the same configuration used by Kelp. This setup means only one validator must sign off on a cross-chain message for the bridge to act on it, leaving the system vulnerable to a single point of failure. Kelp plans to dispute LayerZero's claim that it ignored repeated warnings to move away from this setup, stating that it relied on LayerZero's documentation, defaults, and team guidance to make configuration decisions. Security researchers and other experts in the field have also questioned LayerZero's framing of the incident, suggesting that the company may be deflecting responsibility for its own compromised infrastructure. As the situation continues to unfold, both Kelp DAO and LayerZero have released statements, with Kelp confirming that the 1-of-1 DVN setup reflects LayerZero's documented default configuration and LayerZero stating that it is working to 'harden security across every possible vector for applications'. The incident has sparked a wider conversation about the risks and vulnerabilities associated with cross-chain messaging and the importance of robust security measures in the crypto space.