Kelp DAO Disputes LayerZero's Claim of Responsibility for $290 Million Disaster

A recent crypto controversy is unfolding, with Kelp DAO set to challenge LayerZero's post-mortem analysis of the $290 million exploit that occurred on Sunday. According to a source familiar with the matter, Kelp plans to counter LayerZero's claim that it ignored repeated warnings to move away from a single-verifier setup. The liquid restaking protocol asserts that the compromised verifier was actually LayerZero's own infrastructure and that the setup in question was the default configuration provided by LayerZero. Kelp takes user-deposited ether, routes it through a yield-generating system called EigenLayer, and issues a receipt token, rsETH, in exchange. LayerZero, the cross-chain messaging infrastructure, is responsible for moving rsETH between blockchains using decentralized verifier networks (DVNs) to verify the validity of cross-chain transfers. On Saturday, attackers drained 116,500 rsETH, worth approximately $290 million, from Kelp's LayerZero-powered bridge by poisoning the servers that LayerZero's verifier relied on. Kelp claims that the attackers compromised two of LayerZero's own servers, then flooded the backup servers with junk traffic, forcing LayerZero's verifier onto the compromised ones. The source contested LayerZero's framing of the '1/1 configuration' as a fringe choice made against guidance, stating that LayerZero's post-mortem said KelpDAO chose a 1-of-1 DVN setup despite recommendations to configure multi-DVN redundancy. However, the source added that through a direct communications channel with LayerZero, no specific recommendation was made for Kelp to change the rsETH DVN configuration. Furthermore, LayerZero's own quickstart guide and default GitHub configuration point to a 1/1 DVN setup, with 40% of protocols on LayerZero currently using the same configuration. Security researchers are also skeptical of LayerZero's isolated framing, which pinned the blame on Kelp. Yearn Finance core team developer Artem K posted a technical review of LayerZero's public deployment code, stating that the reference setup ships with single-source verification defaults across every major chain. Chainlink community manager Zach Rynes alleged that LayerZero was 'deflecting responsibility' for its own compromised infrastructure and accused the company of throwing Kelp under the bus for trusting a setup LayerZero itself supported. As a result, LayerZero has said it will no longer sign messages for any application running a single-verifier setup, forcing a protocol-wide migration. In a statement, Kelp DAO confirmed that the 1-of-1 DVN setup at the center of the incident reflects LayerZero’s documented default configuration. The team behind LayerZero is working to 'harden security across every possible vector for applications,' with co-founder Bryan Pellegrino stating that initial investigations had been 'largely resolved' and that the team would publish more updates soon.