Kelp DAO Shifts Blame to LayerZero for $290 Million Loss, Citing Default Settings

A recent crypto incident has sparked a heated debate, with Kelp DAO set to dispute LayerZero's claims that it ignored warnings to change its single-verifier setup. The liquid restaking protocol argues that the compromised verifier was actually part of LayerZero's own infrastructure and that the setup it used was the default recommended by LayerZero. The incident involved the theft of 116,500 rsETH, worth around $290 million, from Kelp's LayerZero-powered bridge due to a sophisticated state-sponsored attack. Kelp claims that the attack compromised two of LayerZero's own servers, which were then used to flood backup servers with junk traffic, forcing LayerZero's verifier onto the compromised ones. The source also contested LayerZero's framing of the '1/1 configuration' as a fringe choice, arguing that LayerZero's own quickstart guide and default GitHub configuration point to a 1/1 DVN setup, which is used by 40% of protocols on LayerZero. Security researchers have also questioned LayerZero's isolated framing, with one researcher noting that LayerZero's reference setup ships with single-source verification defaults across every major chain. The incident has led to a protocol-wide migration, with LayerZero announcing that it will no longer sign messages for any application running a single-verifier setup.