Kelp DAO Challenges LayerZero's Account of $290 Million Disaster, Citing Default Settings as Culprit
A recent incident has sparked a heated debate in the crypto community, with Kelp DAO and LayerZero presenting differing accounts of a $290 million disaster. According to a source familiar with the matter, Kelp DAO plans to refute LayerZero's post-mortem analysis, which essentially blames Kelp for ignoring warnings about its single-verifier setup. Kelp, a liquid restaking protocol, reportedly intends to argue that the compromised verifier was actually part of LayerZero's own infrastructure, and that the setup was based on LayerZero's default configuration. The incident occurred when attackers drained 116,500 rsETH, worth approximately $290 million, from Kelp's LayerZero-powered bridge by poisoning the servers that LayerZero's verifier relied on to verify transactions. Kelp claims that the infrastructure was built and run by LayerZero, not Kelp, and that LayerZero's own quickstart guide and default GitHub configuration recommend a 1/1 DVN setup, which 40% of protocols on LayerZero are currently using. Security researchers have also questioned LayerZero's account, with one expert noting that LayerZero's reference setup ships with single-source verification defaults across every major chain. The debate has sparked a wider discussion about the security risks associated with cross-chain messaging infrastructure and the need for clearer communication and accountability among protocol operators.