Kelp DAO Challenges LayerZero's Account of $290 Million Disaster, Citing Default Settings
A recent $290 million crypto exploit has sparked a heated debate between Kelp DAO and LayerZero. The incident occurred when attackers drained 116,500 rsETH from Kelp's LayerZero-powered bridge by compromising the servers that LayerZero's verifier relied on. Kelp DAO is now pushing back against LayerZero's post-mortem analysis, which blamed Kelp for ignoring warnings about its single-verifier setup. According to a source familiar with the matter, Kelp plans to argue that the compromised verifier was actually part of LayerZero's own infrastructure, not a third-party verifier. The source also contested LayerZero's claim that Kelp chose a 1-of-1 DVN setup despite recommendations to configure multi-DVN redundancy, pointing out that LayerZero's own quickstart guide and default GitHub configuration recommend a 1/1 DVN setup. This configuration is reportedly used by 40% of protocols on LayerZero. Security researchers have also questioned LayerZero's account, with one expert noting that the company's reference setup ships with single-source verification defaults across every major chain. The incident has led to a wider debate about the security risks associated with cross-chain messaging infrastructure and the need for greater transparency and accountability in the crypto industry.