Kelp DAO Disputes LayerZero's Claims Over $290 Million Disaster, Citing Default Settings as Cause

A recent controversy has erupted in the crypto space, with Kelp DAO set to challenge LayerZero's account of the $290 million exploit that occurred on Sunday. According to a source familiar with the matter, Kelp DAO will dispute LayerZero's claim that it was to blame for the incident due to its use of a single-verifier setup. The liquid restaking protocol claims that the compromised verifier was actually part of LayerZero's own infrastructure, and that the setup it was using was based on LayerZero's default onboarding configuration. Kelp DAO takes user-deposited ether, routes it through a yield-generating system called EigenLayer, and issues a receipt token, rsETH, in exchange. LayerZero provides the cross-chain messaging infrastructure that moves rsETH between blockchains, using entities called DVNs to verify the validity of cross-chain transfers. On Saturday, attackers drained 116,500 rsETH, worth about $290 million, from Kelp's LayerZero-powered bridge by compromising the servers that LayerZero's verifier relied on to check transactions. Kelp DAO argues that the DVN that was compromised was LayerZero's own infrastructure, not a third-party verifier, and that the setup it was using was based on LayerZero's default configuration. The source claimed that LayerZero's post-mortem of the incident was misleading, and that the company had not provided any specific recommendations for Kelp to change its rsETH DVN configuration. In fact, LayerZero's own quickstart guide and default GitHub configuration point to a 1/1 DVN setup, which is the same configuration that Kelp was using. Security researchers have also questioned LayerZero's account of the incident, with one expert noting that the company's reference setup ships with single-source verification defaults across every major chain. The incident has sparked a heated debate in the crypto community, with some accusing LayerZero of deflecting responsibility for its own compromised infrastructure. Kelp DAO has confirmed that it will no longer use the single-verifier setup, and will instead migrate to a multi-verifier configuration. The company has also called for a shared and accurate account of what happened, in order to make the necessary fixes and prevent similar incidents in the future.