Kelp DAO Disputes LayerZero's Account of $290 Million Hack, Claims Default Settings Were to Blame

A recent controversy has erupted in the crypto space, with Kelp DAO set to challenge LayerZero's post-mortem analysis of the $290 million exploit that occurred on Sunday. According to a source familiar with the matter, Kelp plans to contest LayerZero's claim that it ignored warnings to move away from a single-verifier setup. The liquid restaking protocol claims that the compromised verifier was actually part of LayerZero's own infrastructure, and that the setup was based on LayerZero's default configuration. The incident involved the draining of 116,500 rsETH, worth around $290 million, from Kelp's LayerZero-powered bridge. Attackers compromised two of LayerZero's servers and flooded the backup servers with traffic, forcing LayerZero's verifier onto the compromised ones. Kelp argues that all of this infrastructure was built and run by LayerZero, not Kelp. The source also contested LayerZero's framing of the '1/1 configuration' as a fringe choice made against guidance, pointing out that LayerZero's own quickstart guide and default GitHub configuration recommend a 1/1 DVN setup. In fact, 40% of protocols on LayerZero are currently using this configuration. Security researchers have also questioned LayerZero's account, with one developer noting that the reference setup ships with single-source verification defaults across every major chain. The incident has sparked a heated debate, with some accusing LayerZero of deflecting responsibility for its own compromised infrastructure. Kelp DAO has stated that it will work with LayerZero to establish a shared and accurate account of what happened, while LayerZero is working to 'harden security across every possible vector for applications'.