Kelp DAO Disputes LayerZero's Claims Regarding $290 Million Disaster
A recent crypto incident has sparked a heated debate, with Kelp DAO set to challenge LayerZero's post-mortem analysis of the $290 million exploit. According to a source familiar with the matter, Kelp plans to argue that the compromised verifier was actually part of LayerZero's own infrastructure, and that the setup in question was the default configuration provided by LayerZero. The incident occurred when attackers drained 116,500 rsETH, worth approximately $290 million, from Kelp's LayerZero-powered bridge by poisoning the servers that relied on LayerZero's verifier to check transactions. Kelp claims that the compromised infrastructure was built and run by LayerZero, not by Kelp itself. The source also contested LayerZero's framing of the '1/1 configuration' as a fringe choice made against guidance, pointing out that LayerZero's own quickstart guide and default GitHub configuration recommend a 1/1 DVN setup. In fact, 40% of protocols on LayerZero are currently using this configuration. Security researchers have also questioned LayerZero's isolated framing, which pinned the blame on Kelp. Yearn Finance core team developer Artem K reviewed LayerZero's public deployment code and found that the reference setup ships with single-source verification defaults across every major chain. Chainlink community manager Zach Rynes accused LayerZero of 'deflecting responsibility' for its own compromised infrastructure and throwing Kelp under the bus for trusting a setup that LayerZero itself supported. Kelp DAO has confirmed that it will no longer use the single-verifier setup, and LayerZero has announced that it will no longer sign messages for any application running this configuration, forcing a protocol-wide migration.