Kelp DAO Disputes LayerZero's Claims Regarding $290 Million Exploit

A recent cryptocurrency exploit has sparked a heated debate between Kelp DAO and LayerZero, with each party assigning blame to the other. The incident in question involved the theft of $290 million from Kelp's LayerZero-powered bridge. According to a source familiar with the matter, Kelp DAO plans to challenge LayerZero's claim that it ignored warnings to change its single-verifier setup. Instead, Kelp asserts that the compromised verifier was part of LayerZero's own infrastructure and that the setup was based on LayerZero's default configuration. Kelp is a liquid restaking protocol that utilizes LayerZero's cross-chain messaging infrastructure to move its receipt token, rsETH, between blockchains. The attack occurred when hackers poisoned the servers that LayerZero's verifier relied on to validate transactions, resulting in the theft of 116,500 rsETH. Kelp claims that the compromised infrastructure was built and run by LayerZero, not by a third-party verifier. The source also contested LayerZero's assertion that Kelp chose a 1-of-1 DVN setup despite recommendations to configure multi-DVN redundancy. Kelp argues that LayerZero's own quickstart guide and default GitHub configuration point to a 1/1 DVN setup, which is also used by 40% of protocols on LayerZero. Security researchers have also questioned LayerZero's framing of the incident, with one expert noting that LayerZero's reference setup ships with single-source verification defaults across every major chain. The incident has sparked a wider debate about the security of cryptocurrency protocols and the need for greater transparency and accountability.