Kelp DAO disputes LayerZero's claims, asserts 'default' settings led to $290 million loss
A recent crypto incident has sparked a heated debate, with Kelp DAO set to challenge LayerZero's post-mortem analysis of the $290 million exploit that occurred on Sunday. According to a source familiar with the matter, Kelp DAO plans to contest LayerZero's claim that it ignored warnings to change its single-verifier setup. The liquid restaking protocol takes user-deposited ether, routes it through a yield-generating system, and issues a receipt token. LayerZero provides the cross-chain messaging infrastructure that moves this token between blockchains, using decentralized verifier networks to verify transactions. On Saturday, attackers drained $290 million worth of tokens by poisoning the servers that LayerZero's verifier relied on. Kelp DAO claims that the compromised verifier was part of LayerZero's own infrastructure, not a third-party verifier, and that the setup was based on LayerZero's default configuration. The source also contested LayerZero's framing of the '1/1 configuration' as a fringe choice, stating that LayerZero's quickstart guide and default GitHub configuration point to a 1/1 DVN setup. Security researchers have also questioned LayerZero's isolated framing, which pinned the blame on Kelp DAO. Yearn Finance core team developer Artem K reviewed LayerZero's public deployment code and found that the reference setup ships with single-source verification defaults. Chainlink community manager Zach Rynes accused LayerZero of deflecting responsibility for its own compromised infrastructure. Kelp DAO has confirmed that the 1-of-1 DVN setup reflects LayerZero's documented default configuration and has operated on LayerZero infrastructure since January 2024. The team behind LayerZero is working to harden security across every possible vector for applications.