Kelp DAO Shifts Blame to LayerZero for $290 Million Loss, Citing Default Settings
A recent incident has sparked a heated debate in the crypto community, with Kelp DAO and LayerZero pointing fingers at each other over a $290 million loss. According to a source familiar with the matter, Kelp DAO is set to dispute LayerZero's claim that it ignored warnings to change its single-verifier setup. The liquid restaking protocol claims that the compromised verifier was actually part of LayerZero's own infrastructure, and that the setup it was using was the default configuration provided by LayerZero. The incident occurred when attackers drained 116,500 rsETH, worth around $290 million, from Kelp's LayerZero-powered bridge by poisoning the servers that LayerZero's verifier relied on to check transactions. Kelp claims that the attack was made possible by a 'sophisticated state-sponsored attack' that compromised two of LayerZero's own servers, which were then used to flood the backup servers with junk traffic. The source also contested LayerZero's framing of the '1/1 configuration' as a fringe choice made against guidance, pointing out that LayerZero's own quickstart guide and default GitHub configuration recommend a 1/1 DVN setup. In fact, 40% of protocols on LayerZero are currently using the same configuration. Security researchers have also weighed in on the issue, with some accusing LayerZero of 'deflecting responsibility' for its own compromised infrastructure. Yearn Finance core team developer Artem K, also known as @banteg, posted a technical review of LayerZero's public deployment code, noting that the reference setup ships with single-source verification defaults across every major chain. Chainlink community manager Zach Rynes was more blunt, alleging that LayerZero was 'deflecting responsibility' for its own compromised infrastructure and accusing the company of throwing Kelp under the bus for trusting a setup that LayerZero itself supported. In response to the incident, LayerZero has announced that it will no longer sign messages for any application running a single-verifier setup, forcing a protocol-wide migration. Kelp DAO has confirmed that it will work with LayerZero to establish a shared and accurate account of what happened and to make the necessary fixes. The team behind LayerZero is also working to 'harden security across every possible vector for applications', with co-founder Bryan Pellegrino stating that the initial investigations had been 'largely resolved' and that the team would publish more updates soon.