Kelp DAO Shifts Blame to LayerZero for $290 Million Disaster, Citing Default Settings
A recent cryptocurrency exploit has sparked a heated debate, with Kelp DAO pushing back against LayerZero's post-mortem analysis of the $290 million disaster. According to a source familiar with the matter, Kelp plans to argue that the compromised verifier was actually part of LayerZero's own infrastructure, not a third-party verifier, and that the setup was based on LayerZero's default onboarding configuration. The incident occurred when attackers drained 116,500 rsETH, worth approximately $290 million, from Kelp's LayerZero-powered bridge by poisoning the servers that LayerZero's verifier relied on to check transactions. Kelp, a liquid restaking protocol, takes user-deposited ether and routes it through a yield-generating system called EigenLayer, issuing a receipt token, rsETH, in exchange. LayerZero, the cross-chain messaging infrastructure, moves rsETH between blockchains using entities called DVNs to verify cross-chain transfers. The source claimed that the DVN that was compromised was LayerZero's own infrastructure, not a third-party verifier, and that the attackers compromised two of LayerZero's servers, then flooded the backup servers with junk traffic to force LayerZero's verifier onto the compromised ones. Kelp is planning to dispute LayerZero's claim that it ignored repeated warnings to move away from a single-verifier setup, stating that the configuration was based on LayerZero's own quickstart guide and default GitHub configuration. Security researchers have also questioned LayerZero's framing of the incident, with one researcher noting that LayerZero's reference setup ships with single-source verification defaults across every major chain. The incident has sparked a wider debate about the security of cryptocurrency infrastructure, with some accusing LayerZero of deflecting responsibility for its own compromised infrastructure.