Kelp DAO Disputes LayerZero's Claims Regarding $290 Million Loss
A recent crypto controversy has sparked debate, with Kelp DAO set to challenge LayerZero's account of a $290 million exploit. According to a source familiar with the matter, Kelp plans to argue that the compromised verifier was part of LayerZero's own infrastructure and that the setup in question was LayerZero's default configuration. The issue began when attackers drained approximately $290 million worth of rsETH from Kelp's LayerZero-powered bridge by compromising the servers that LayerZero's verifier relied on. Kelp, a liquid restaking protocol, takes user-deposited ether and routes it through a yield-generating system, issuing a receipt token in exchange. The protocol relies on LayerZero for cross-chain messaging, using entities called decentralized verifier networks (DVNs) to verify transactions. The source claims that the DVN compromised in the attack was LayerZero's own infrastructure, not a third-party verifier. Furthermore, the attack allegedly involved compromising two of LayerZero's servers and then overwhelming the backup servers with traffic to force LayerZero's verifier onto the compromised servers. All of this infrastructure was built and run by LayerZero, not Kelp. The source disputes LayerZero's claim that Kelp chose a 1-of-1 DVN setup despite recommendations to configure multi-DVN redundancy. Instead, Kelp argues that LayerZero's own quickstart guide and default GitHub configuration point to a 1/1 DVN setup, which 40% of protocols on LayerZero are currently using. Security researchers have also questioned LayerZero's framing of the incident, with one expert noting that LayerZero's reference setup ships with single-source verification defaults across every major chain. The incident has led to a wider debate about responsibility and security in the crypto space, with some accusing LayerZero of deflecting blame. In response to the incident, LayerZero has announced that it will no longer sign messages for any application running a single-verifier setup, prompting a protocol-wide migration.