Kelp DAO Shifts Blame to LayerZero for $290 Million Disaster, Citing 'Default' Settings
A recent cryptocurrency exploit has sparked a heated debate, with Kelp DAO set to dispute LayerZero's claim that it ignored warnings about its single-verifier setup. Kelp plans to argue that the compromised verifier was part of LayerZero's own infrastructure and that the setup was based on LayerZero's default onboarding configuration. The incident involved a $290 million exploit, which occurred when attackers poisoned the servers used by LayerZero's verifier to check transactions. Kelp, a liquid restaking protocol, takes user-deposited ether and issues a receipt token, rsETH, in exchange. LayerZero is the cross-chain messaging infrastructure that moves rsETH between blockchains. The attackers compromised two of LayerZero's servers, then flooded the backup servers with junk traffic to force LayerZero's verifier onto the compromised ones. Kelp claims that all of this infrastructure was built and run by LayerZero, not Kelp. The source contested LayerZero's framing of the '1/1 configuration' as a fringe choice made against guidance, stating that LayerZero's own quickstart guide and default GitHub configuration point to a 1/1 DVN setup. Security researchers are also skeptical of LayerZero's isolated framing, which pinned the blame on Kelp. Yearn Finance core team developer Artem K posted a technical review of LayerZero's public deployment code, stating that the reference setup ships with single-source verification defaults across every major chain. Chainlink community manager Zach Rynes alleged that LayerZero was 'deflecting responsibility' for its own compromised infrastructure and accused the company of throwing Kelp under the bus for trusting a setup LayerZero itself supported. Kelp DAO confirmed that the 1-of-1 DVN setup at the center of the incident reflects LayerZero's documented default configuration.