Kelp DAO Disputes LayerZero's Claims on $290 Million Disaster, Citing Default Settings as Culprit

A recent cryptocurrency exploit has sparked a heated debate between Kelp DAO and LayerZero, with Kelp set to contest LayerZero's post-mortem analysis of the $290 million disaster. According to a source familiar with the matter, Kelp plans to claim that the compromised verifier was actually part of LayerZero's own infrastructure, and that the setup was based on LayerZero's default configuration. The incident occurred when attackers drained 116,500 rsETH, worth approximately $290 million, from Kelp's LayerZero-powered bridge by poisoning the servers that LayerZero's verifier relied on to verify transactions. Kelp, a liquid restaking protocol, takes user-deposited ether, routes it through a yield-generating system called EigenLayer, and issues a receipt token, rsETH, in exchange. LayerZero, on the other hand, provides the cross-chain messaging infrastructure that moves rsETH between blockchains, using entities called DVNs to verify the validity of cross-chain transfers. The source claims that attackers compromised two of LayerZero's own servers, which were used to check the legitimacy of cross-chain transactions, and then flooded the backup servers with junk traffic to force LayerZero's verifier onto the compromised ones. Kelp contests LayerZero's claim that it ignored repeated warnings to move away from a single-verifier setup, arguing that the configuration was based on LayerZero's default settings. The incident has sparked a wider debate about the security of cryptocurrency protocols, with some security researchers and experts questioning LayerZero's decision to blame Kelp for the exploit. Yearn Finance core team developer Artem K, also known as @banteg on X, has posted a technical review of LayerZero's public deployment code, noting that the reference setup ships with single-source verification defaults across every major chain. Chainlink community manager Zach Rynes has also accused LayerZero of deflecting responsibility for its own compromised infrastructure. In response to the incident, LayerZero has announced that it will no longer sign messages for any application running a single-verifier setup, forcing a protocol-wide migration. Kelp DAO has confirmed that the 1-of-1 DVN setup at the center of the incident reflects LayerZero's documented default configuration, and has called for a shared and accurate account of what happened to be established in order to make the necessary fixes.