Kelp DAO Disputes LayerZero's Account of $290 Million Exploit, Citing Default Settings as the Cause
A recent crypto controversy is unfolding as Kelp DAO prepares to challenge LayerZero's analysis of the $290 million exploit that occurred on Sunday. According to a source familiar with the matter, Kelp plans to argue that the cross-chain messaging firm's claim that Kelp ignored warnings about its single-verifier setup is inaccurate. Instead, Kelp will assert that the compromised decentralized verifier network (DVN) was part of LayerZero's own infrastructure, not a third-party verifier. The incident involved the poisoning of servers that LayerZero's verifier relied on to validate transactions, resulting in the theft of 116,500 rsETH, worth approximately $290 million, from Kelp's LayerZero-powered bridge. Kelp, a liquid restaking protocol, takes user-deposited ether, routes it through a yield-generating system called EigenLayer, and issues a receipt token, rsETH, in exchange. LayerZero is the cross-chain messaging infrastructure that facilitates the movement of rsETH between blockchains using DVNs to verify the validity of cross-chain transfers. The source claims that the attack was a sophisticated state-sponsored attack that compromised two of LayerZero's own servers, which were then used to flood backup servers with junk traffic, forcing LayerZero's verifier onto the compromised servers. All of the infrastructure involved was built and run by LayerZero, not Kelp. The source also contests LayerZero's characterization of the 1/1 configuration as a fringe choice made against guidance, pointing out that LayerZero's own quickstart guide and default GitHub configuration recommend a 1/1 DVN setup, which is currently used by 40% of protocols on LayerZero. Security researchers are also skeptical of LayerZero's account, with one expert noting that the reference setup ships with single-source verification defaults across every major chain and leaves a public endpoint exposed. The incident has sparked a debate about responsibility, with some accusing LayerZero of deflecting blame and throwing Kelp under the bus for trusting a setup that LayerZero itself supported. In response to the incident, LayerZero has announced that it will no longer sign messages for any application running a single-verifier setup, forcing a protocol-wide migration. Kelp DAO has confirmed that the 1-of-1 DVN setup at the center of the incident reflects LayerZero's documented default configuration and has called for a shared and accurate account of what happened to make the necessary fixes.