Kelp DAO Disputes LayerZero's Account of $290 Million Hack, Citing Default Settings as Culprit
A recent crypto controversy has drawn comparisons to a popular Spiderman meme, where three identical superheroes point fingers at each other. In this case, Kelp DAO is pushing back against LayerZero's post-mortem of the $290 million exploit that occurred on Sunday. According to a source familiar with the matter, Kelp plans to dispute LayerZero's claim that it ignored warnings to move away from a single-verifier setup. The liquid restaking protocol takes user-deposited ether, routes it through a yield-generating system, and issues a receipt token. However, on Saturday, attackers drained 116,500 of these tokens, worth about $290 million, by poisoning the servers that LayerZero's verifier relied on. Kelp claims that the compromised verifier was actually LayerZero's own infrastructure, not a third-party verifier, and that the setup it was faulted for running was LayerZero's onboarding default. The source also contested LayerZero's framing of the '1/1 configuration' as a fringe choice made against guidance, stating that LayerZero's own quickstart guide and default GitHub configuration point to a 1/1 DVN setup. Security researchers have also questioned LayerZero's isolated framing, which pinned the blame on Kelp. As the situation continues to unfold, both parties are working to establish a shared account of what happened and make the necessary fixes to prevent similar incidents in the future.