Kelp DAO Disputes LayerZero's Account of $290 Million Exploit, Claims Default Settings Were to Blame
A recent $290 million disaster has sparked a heated debate between Kelp DAO and LayerZero, with Kelp set to challenge LayerZero's post-mortem of the incident. According to a source familiar with the matter, Kelp plans to dispute LayerZero's claim that it ignored warnings to move away from a single-verifier setup. The liquid restaking protocol takes user-deposited ether, routes it through a yield-generating system, and issues a receipt token. LayerZero's cross-chain messaging infrastructure was used to move this token between blockchains, but attackers drained $290 million from Kelp's bridge by poisoning the servers that LayerZero's verifier relied on. Kelp claims that the compromised verifier was part of LayerZero's own infrastructure, not a third-party verifier, and that the setup was based on LayerZero's default configuration. The source contested LayerZero's framing of the '1/1 configuration' as a fringe choice made against guidance, stating that LayerZero's own quickstart guide and default GitHub configuration point to a 1/1 DVN setup. Security researchers have also questioned LayerZero's isolated framing, which pinned the blame on Kelp. Yearn Finance core team developer Artem K posted a technical review of LayerZero's public deployment code, noting that the reference setup ships with single-source verification defaults across every major chain. Chainlink community manager Zach Rynes accused LayerZero of 'deflecting responsibility' for its own compromised infrastructure and throwing Kelp under the bus for trusting a setup LayerZero itself supported. Kelp DAO has confirmed that the 1-of-1 DVN setup reflects LayerZero's documented default configuration and has operated on LayerZero infrastructure since January 2024, maintaining close communication with the LayerZero team.