Kelp DAO Disputes LayerZero's Claims Over $290 Million Exploit

A recent crypto controversy has erupted, with Kelp DAO set to challenge LayerZero's account of the $290 million exploit that occurred on Sunday. According to a source familiar with the matter, Kelp DAO plans to contest LayerZero's claim that it ignored warnings to change its single-verifier setup. The liquid restaking protocol claims that the compromised verifier was actually part of LayerZero's own infrastructure and that the setup was based on LayerZero's default configuration. The incident involved the theft of 116,500 rsETH, worth approximately $290 million, from Kelp's LayerZero-powered bridge. Attackers compromised two of LayerZero's servers, which were used to verify cross-chain transactions, and then flooded the backup servers with junk traffic to force LayerZero's verifier onto the compromised ones. Kelp DAO argues that all of this infrastructure was built and run by LayerZero, not by Kelp. The source also contested LayerZero's framing of the '1/1 configuration' as a fringe choice made against guidance, stating that LayerZero's own quickstart guide and default GitHub configuration point to a 1/1 DVN setup, which is also used by 40% of protocols on LayerZero. Security researchers have also questioned LayerZero's isolated framing, which pinned the blame on Kelp. Yearn Finance core team developer Artem K posted a technical review of LayerZero's public deployment code, noting that the reference setup ships with single-source verification defaults across every major chain. Chainlink community manager Zach Rynes accused LayerZero of 'deflecting responsibility' for its own compromised infrastructure and throwing Kelp under the bus for trusting a setup that LayerZero itself supported. Kelp DAO has confirmed that it will no longer use the single-verifier setup and will work with LayerZero to establish a shared and accurate account of what happened. LayerZero has stated that it will no longer sign messages for any application running a single-verifier setup and is working to 'harden security across every possible vector for applications'.