Kelp DAO Disputes LayerZero's Claims Over $290 Million Disaster, Alleging Default Settings Were to Blame
A recent crypto controversy has drawn comparisons to a popular Spiderman meme, where three identical superheroes point fingers at each other. This time, Kelp DAO and LayerZero are at the center of the dispute. Kelp DAO is pushing back against LayerZero's claims that it was responsible for the $290 million exploit that occurred on Sunday. According to a source familiar with the matter, Kelp plans to argue that the compromised verifier was actually LayerZero's own infrastructure and that the setup it was criticized for using was LayerZero's default configuration. Kelp is a liquid restaking protocol that takes user-deposited ether and issues a receipt token, rsETH, in exchange. LayerZero provides the cross-chain messaging infrastructure that moves rsETH between blockchains, using entities called decentralized verifier networks (DVNs) to verify transactions. On Saturday, attackers drained 116,500 rsETH, worth about $290 million, from Kelp's LayerZero-powered bridge by poisoning the servers that LayerZero's verifier relied on. Kelp claims that the DVN that was compromised was LayerZero's own infrastructure, not a third-party verifier, and that the attack was a sophisticated state-sponsored attack. The source also contested LayerZero's claim that Kelp chose a 1-of-1 DVN setup despite recommendations to configure multi-DVN redundancy. Instead, Kelp argues that LayerZero's own quickstart guide and default GitHub configuration point to a 1/1 DVN setup, which is also used by 40% of protocols on LayerZero. Security researchers have also questioned LayerZero's framing of the incident, with one researcher noting that LayerZero's reference setup ships with single-source verification defaults across every major chain. The incident has led to a protocol-wide migration, with LayerZero announcing that it will no longer sign messages for any application running a single-verifier setup. Kelp DAO has confirmed that it used LayerZero's documented default configuration and has operated on LayerZero infrastructure since January 2024, maintaining close communication with the LayerZero team.