Kelp DAO Disputes LayerZero's Claims Regarding $290 Million Exploit
A recent crypto controversy is unfolding, with Kelp DAO set to challenge LayerZero's account of the $290 million exploit that occurred on Sunday. According to a source familiar with the matter, Kelp plans to contest LayerZero's claim that it ignored warnings to move away from a single-verifier setup. Kelp is a liquid restaking protocol that uses LayerZero's cross-chain messaging infrastructure to transfer its receipt token, rsETH, between blockchains. The attackers exploited a vulnerability in LayerZero's verifier, draining 116,500 rsETH worth approximately $290 million from Kelp's bridge. Kelp claims that the compromised verifier was part of LayerZero's own infrastructure, not a third-party verifier, and that the setup was based on LayerZero's default configuration. The source also contested LayerZero's framing of the '1/1 configuration' as a fringe choice made against guidance, pointing out that LayerZero's own quickstart guide and default GitHub configuration recommend a 1/1 DVN setup. Security researchers have also questioned LayerZero's isolated framing, which pinned the blame on Kelp. Yearn Finance core team developer Artem K reviewed LayerZero's public deployment code and found that the reference setup ships with single-source verification defaults across every major chain. Chainlink community manager Zach Rynes accused LayerZero of deflecting responsibility for its own compromised infrastructure and throwing Kelp under the bus for trusting a setup LayerZero itself supported. Kelp DAO has confirmed that the 1-of-1 DVN setup reflects LayerZero's documented default configuration and has operated on LayerZero infrastructure since January 2024, maintaining close communication with the LayerZero team.