Kelp DAO Disputes LayerZero's Claims Regarding $290 Million Hack, Citing Default Settings as the Cause

A recent $290 million exploit has sparked a heated debate between Kelp DAO and LayerZero, with Kelp set to challenge LayerZero's post-mortem analysis of the incident. According to a source familiar with the matter, Kelp plans to dispute LayerZero's claim that it ignored repeated warnings to move away from a single-verifier setup. The liquid restaking protocol claims that the compromised verifier was actually part of LayerZero's own infrastructure, and the setup that was faulted was the default configuration provided by LayerZero. The incident occurred when attackers drained 116,500 rsETH, worth about $290 million, from Kelp's LayerZero-powered bridge by poisoning the servers that LayerZero's verifier relied on to check transactions. Kelp argues that the attackers compromised two of LayerZero's own servers, which were built and run by LayerZero, and not by a third-party verifier. The source also contested LayerZero's framing of the '1/1 configuration' as a fringe choice made against guidance, stating that LayerZero's own quickstart guide and default GitHub configuration point to a 1/1 DVN setup. Security researchers have also questioned LayerZero's isolated framing, which pinned the blame on Kelp, with some accusing LayerZero of 'deflecting responsibility' for its own compromised infrastructure. The incident has led to a protocol-wide migration, with LayerZero announcing that it will no longer sign messages for any application running a single-verifier setup.