Kelp DAO Counters LayerZero's Claims, Asserts 'Default' Settings Led to $290 Million Loss
A recent cryptocurrency exploit has sparked a heated debate, with Kelp DAO set to dispute LayerZero's claims regarding the $290 million disaster that occurred on Sunday. A source familiar with the matter revealed that Kelp plans to argue that the compromised verifier was part of LayerZero's own infrastructure, not a third-party entity, and that the setup in question was the default configuration provided by LayerZero. The incident involved the draining of 116,500 rsETH, worth approximately $290 million, from Kelp's LayerZero-powered bridge due to a 'sophisticated state-sponsored attack' that poisoned the servers used by LayerZero's verifier. Kelp claims that the attackers compromised two of LayerZero's servers, which were then used to flood backup servers with junk traffic, forcing LayerZero's verifier onto the compromised servers. The source emphasized that all of the infrastructure involved was built and run by LayerZero, not Kelp. Furthermore, Kelp disputes LayerZero's assertion that it chose a 1-of-1 DVN setup despite recommendations to configure multi-DVN redundancy, stating that LayerZero's own quickstart guide and default GitHub configuration point to a 1/1 DVN setup. In fact, 40% of protocols on LayerZero are currently using the same configuration. Security researchers have also questioned LayerZero's framing of the incident, with some accusing the company of 'deflecting responsibility' for its own compromised infrastructure. Yearn Finance core team developer Artem K, also known as @banteg, posted a technical review of LayerZero's public deployment code, noting that the reference setup ships with single-source verification defaults across every major chain. Chainlink community manager Zach Rynes alleged that LayerZero was 'deflecting responsibility' for its own compromised infrastructure and accused the company of throwing Kelp under the bus for trusting a setup that LayerZero itself supported. As a result, LayerZero has announced that it will no longer sign messages for any application running a single-verifier setup, prompting a protocol-wide migration. In a statement, Kelp DAO confirmed that the 1-of-1 DVN setup at the center of the incident reflects LayerZero's documented default configuration and emphasized the need to establish a shared and accurate account of what happened to make the necessary fixes.