Kelp DAO Disputes LayerZero's Claims Over $290 Million Disaster, Citing Default Settings as the Cause
A recent cryptocurrency incident has sparked a heated debate, with Kelp DAO set to challenge LayerZero's account of the $290 million exploit that occurred on Sunday. According to a source familiar with the matter, Kelp DAO plans to counter LayerZero's claim that the protocol ignored warnings about its single-verifier setup. Kelp DAO is a liquid restaking protocol that utilizes user-deposited ether, routing it through a yield-generating system called EigenLayer, and issuing a receipt token, rsETH, in exchange. LayerZero, on the other hand, is the cross-chain messaging infrastructure responsible for moving rsETH between blockchains, relying on decentralized verifier networks (DVNs) to verify the validity of cross-chain transfers. On Saturday, attackers drained 116,500 rsETH, worth approximately $290 million, from Kelp's LayerZero-powered bridge by compromising the servers that LayerZero's verifier relied on to check transactions. Kelp DAO claims that the compromised DVN was actually LayerZero's own infrastructure, not a third-party verifier, and that the setup in question was the default configuration provided by LayerZero. The source also contested LayerZero's characterization of the '1/1 configuration' as a fringe choice made against guidance, pointing out that LayerZero's own quickstart guide and default GitHub configuration recommend a 1/1 DVN setup, which is currently used by 40% of protocols on LayerZero. Security researchers have also questioned LayerZero's account, with one expert noting that the reference setup ships with single-source verification defaults across every major chain, including Ethereum, BSC, Polygon, Arbitrum, and Optimism. Furthermore, the deployment leaves a public endpoint exposed, allowing anyone to query and obtain the list of configured servers. As the situation continues to unfold, Kelp DAO has stated that it has operated on LayerZero infrastructure since January 2024 and maintained close communication with the LayerZero team, including during its L2 expansion when the default configuration was explicitly confirmed as appropriate. The team behind LayerZero is working to 'harden security across every possible vector for applications,' with co-founder Bryan Pellegrino stating that the initial investigations had been 'largely resolved' and that the team would publish more updates soon.