Kelp DAO Disputes LayerZero's Claims Regarding $290 Million Disaster

A recent crypto controversy has erupted, with Kelp DAO set to contest LayerZero's analysis of the $290 million exploit that occurred on Sunday. According to a source familiar with the matter, Kelp plans to argue that the cross-chain messaging firm's claim that it ignored warnings about its single-verifier setup is unfounded. The liquid restaking protocol, which operates by routing user-deposited ether through a yield-generating system and issuing receipt tokens, asserts that the compromised verifier was actually part of LayerZero's own infrastructure, not a third-party entity. This assertion is based on the fact that attackers compromised two of LayerZero's servers, which were then used to flood backup servers with junk traffic, forcing LayerZero's verifier onto the compromised servers. All of this infrastructure, Kelp claims, was built and run by LayerZero, not by them. Furthermore, Kelp contests LayerZero's framing of the '1/1 configuration' as a fringe choice, stating that this setup was actually LayerZero's default configuration, as indicated in their quickstart guide and GitHub configuration. Approximately 40% of protocols on LayerZero are currently using the same configuration, according to the source. Security researchers have also expressed skepticism regarding LayerZero's isolated framing, which places blame solely on Kelp. Yearn Finance core team developer Artem K, also known as @banteg, has posted a technical review of LayerZero's public deployment code, noting that the reference setup ships with single-source verification defaults across every major chain. Chainlink community manager Zach Rynes has accused LayerZero of deflecting responsibility for its own compromised infrastructure and throwing Kelp under the bus for trusting a setup that LayerZero itself supported. In response to the incident, LayerZero has announced that it will no longer sign messages for any application running a single-verifier setup, prompting a protocol-wide migration. Kelp DAO has confirmed that the 1-of-1 DVN setup at the center of the incident reflects LayerZero's documented default configuration, and the team has called for establishing a shared and accurate account of what happened to make the necessary fixes together.