Kelp DAO Disputes LayerZero's Claims Over $290 Million Loss
A recent crypto controversy has sparked a heated debate, with Kelp DAO set to challenge LayerZero's account of the $290 million exploit that occurred on Sunday. According to a source familiar with the matter, Kelp plans to counter LayerZero's claim that it was to blame for the incident due to its use of a single-verifier setup. The liquid restaking protocol asserts that the compromised verifier was actually part of LayerZero's own infrastructure, and that the setup it was criticized for using was, in fact, LayerZero's default configuration. Kelp takes user-deposited ether, channels it through a yield-generating system called EigenLayer, and issues a receipt token called rsETH in exchange. LayerZero provides the cross-chain messaging infrastructure that facilitates the movement of rsETH between blockchains, utilizing entities known as decentralized verifier networks (DVNs) to verify the legitimacy of cross-chain transactions. On Saturday, attackers drained approximately 116,500 rsETH, worth around $290 million, from Kelp's LayerZero-powered bridge by compromising the servers that LayerZero's verifier relied on to validate transactions. Kelp claims that the DVN compromised in the attack was LayerZero's own infrastructure, not a third-party verifier, and that the attackers targeted two of LayerZero's servers responsible for verifying the legitimacy of cross-chain transactions. The source also contested LayerZero's characterization of the '1/1 configuration' as an unconventional choice made against guidance, stating that LayerZero's post-mortem wrongly suggested that KelpDAO chose a 1-of-1 DVN setup despite recommendations to configure multi-DVN redundancy. A '1/1 configuration' means that only a single validator must sign off on a cross-chain message for the bridge to act on it, leaving the system vulnerable to a single point of failure. In contrast, a multi-validator configuration ensures that there is no single point of failure capable of approving a forged message on its own. Kelp argues that, through direct communication with LayerZero, no specific recommendation was made to change the rsETH DVN configuration. Furthermore, LayerZero's own quickstart guide and default GitHub configuration point to a 1/1 DVN setup, with the source adding that 40% of protocols on LayerZero currently use the same configuration. The configuration Kelp used also appears in LayerZero's own V2 OApp Quickstart, where the sample layerzero.config.ts wires every pathway with one required DVN and no optional DVNs, which is the same 1/1 structure. Kelp's core restaking contracts were not affected, and the exploit was contained to the bridge layer, with the emergency pause, implemented 46 minutes after the drain, blocking two follow-up attempts that would have released an additional ~$200 million in rsETH. Security researchers have also questioned LayerZero's isolated framing, which pinned the blame on Kelp. Yearn Finance core team developer Artem K posted a technical review of LayerZero's public deployment code, stating that the reference setup ships with single-source verification defaults across every major chain, including Ethereum, BSC, Polygon, Arbitrum, and Optimism. Chainlink community manager Zach Rynes accused LayerZero of deflecting responsibility for its own compromised infrastructure and throwing Kelp under the bus for trusting a setup that LayerZero itself supported. As a result, LayerZero has announced that it will no longer sign messages for any application running a single-verifier setup, forcing a protocol-wide migration. In a statement, Kelp DAO confirmed that the 1-of-1 DVN setup at the center of the incident reflects LayerZero's documented default configuration, adding that it has operated on LayerZero infrastructure since January 2024 and maintained close communication with the LayerZero team. The team behind LayerZero is working to 'harden security across every possible vector for applications,' with co-founder Bryan Pellegrino stating that the initial investigations had been 'largely resolved' and that the team would publish more updates soon.