Kelp DAO Disputes LayerZero's Claims Over $290 Million Hack, Points to Default Settings
A recent crypto controversy has drawn comparisons to a popular Spiderman meme, where three identical superheroes point fingers at each other. This time, it's Kelp DAO and LayerZero at the center of the dispute. Following a $290 million exploit on Sunday, LayerZero published a post-mortem that essentially blamed Kelp for ignoring warnings about its single-verifier setup. However, a source familiar with the matter told CoinDesk that Kelp plans to push back against these claims. Kelp is a liquid restaking protocol that works with user-deposited ether, routing it through a yield-generating system called EigenLayer and issuing a receipt token called rsETH in exchange. LayerZero provides the cross-chain messaging infrastructure that moves rsETH between blockchains, using decentralized verifier networks (DVNs) to verify the validity of cross-chain transfers. The recent attack involved the compromise of two of LayerZero's own servers, which were used to check the legitimacy of transactions. These servers were then flooded with junk traffic, forcing LayerZero's verifier to rely on the compromised servers. According to the source, all of this infrastructure was built and run by LayerZero, not Kelp. The source also contested LayerZero's claim that Kelp chose a 1-of-1 DVN setup despite recommendations to configure multi-DVN redundancy. A 1/1 configuration means that only one validator must sign off on a cross-chain message for the bridge to act on it, leaving the system with no second check to catch a compromised or forged instruction. The source argued that LayerZero's own quickstart guide and default GitHub configuration point to a 1/1 DVN setup, which is also used by 40% of protocols on LayerZero. Kelp's core restaking contracts were not touched during the exploit, and the emergency pause 46 minutes after the drain blocked two follow-up attempts that would have released an additional $200 million in rsETH. Security researchers have also questioned LayerZero's framing of the incident, with some accusing the company of deflecting responsibility for its own compromised infrastructure. Yearn Finance core team developer Artem K posted a technical review of LayerZero's public deployment code, noting that the reference setup ships with single-source verification defaults across every major chain. Chainlink community manager Zach Rynes alleged that LayerZero was deflecting responsibility and throwing Kelp under the bus for trusting a setup that LayerZero itself supported. In response to the incident, LayerZero has announced that it will no longer sign messages for any application running a single-verifier setup, forcing a protocol-wide migration. Kelp DAO has confirmed that the 1-of-1 DVN setup at the center of the incident reflects LayerZero's documented default configuration and has maintained close communication with the LayerZero team. The team behind LayerZero is working to harden security across every possible vector for applications, with co-founder Bryan Pellegrino stating that the initial investigations had been largely resolved and that the team would publish more updates soon.