Kelp DAO Disputes LayerZero's Account of $290 Million Exploit, Claims Default Settings Were to Blame
A recent cryptocurrency exploit has sparked a heated debate between Kelp DAO and LayerZero, with Kelp set to challenge LayerZero's post-mortem analysis of the $290 million disaster. According to a source familiar with the matter, Kelp plans to argue that the compromised verifier was actually part of LayerZero's own infrastructure, and that the setup it was criticized for was based on LayerZero's default configuration. The incident occurred when attackers drained 116,500 rsETH, worth approximately $290 million, from Kelp's LayerZero-powered bridge by poisoning the servers that LayerZero's verifier relied on to verify transactions. Kelp claims that the attackers compromised two of LayerZero's own servers, then flooded the backup servers with junk traffic to force LayerZero's verifier onto the compromised ones. The source contested LayerZero's framing of the '1/1 configuration' as a fringe choice made against guidance, stating that LayerZero's own quickstart guide and default GitHub configuration point to a 1/1 DVN setup, which is also used by 40% of protocols on LayerZero. Security researchers have also questioned LayerZero's account, with one researcher noting that the reference setup ships with single-source verification defaults across every major chain, including Ethereum, BSC, Polygon, Arbitrum, and Optimism. The incident has led to a wider debate about the security of cryptocurrency protocols and the potential risks of relying on third-party infrastructure. In response to the incident, LayerZero has announced that it will no longer sign messages for any application running a single-verifier setup, forcing a protocol-wide migration. Kelp DAO has confirmed that it will work with LayerZero to establish a shared and accurate account of what happened and to make the necessary fixes to prevent similar incidents in the future.