Kelp DAO Disputes LayerZero's Account of $290 Million Exploit, Citing Default Settings as the Cause

A recent incident has sparked a heated debate in the crypto community, with Kelp DAO set to challenge LayerZero's post-mortem of the $290 million exploit that occurred on Sunday. According to a source familiar with the matter, Kelp plans to argue that the cross-chain messaging firm's claim that it ignored warnings to move away from a single-verifier setup is inaccurate. The dispute centers around the role of LayerZero's default settings in the exploit. Kelp, a liquid restaking protocol, takes user-deposited ether and issues a receipt token, rsETH, in exchange. The token is then moved between blockchains using LayerZero's infrastructure, which relies on decentralized verifier networks (DVNs) to verify cross-chain transfers. On Saturday, attackers drained 116,500 rsETH, worth approximately $290 million, from Kelp's LayerZero-powered bridge by compromising the servers that LayerZero's verifier relied on. Kelp claims that the compromised DVN was part of LayerZero's own infrastructure, not a third-party verifier, and that the setup was based on LayerZero's default configuration. The source contested LayerZero's framing of the '1/1 configuration' as a fringe choice, stating that LayerZero's own quickstart guide and default GitHub configuration point to a 1/1 DVN setup. Security researchers have also questioned LayerZero's account, with one researcher noting that the reference setup ships with single-source verification defaults across every major chain. The incident has sparked a wider debate about the security of cross-chain messaging infrastructure and the role of default settings in exploits. As the situation continues to unfold, both Kelp DAO and LayerZero have released statements, with Kelp confirming that the 1-of-1 DVN setup reflects LayerZero's documented default configuration and LayerZero stating that it is working to 'harden security across every possible vector for applications'.