Kelp DAO Disputes LayerZero's Claims Over $290 Million Exploit

A recent crypto controversy has sparked debate, with Kelp DAO set to challenge LayerZero's account of the $290 million exploit that occurred on Sunday. According to a source familiar with the matter, Kelp DAO plans to contest LayerZero's claim that it ignored warnings about its single-verifier setup. Instead, Kelp DAO will argue that the compromised verifier was actually part of LayerZero's own infrastructure and that the setup in question was the default configuration provided by LayerZero. The incident involved the drainage of 116,500 rsETH, worth approximately $290 million, from Kelp's LayerZero-powered bridge after attackers poisoned the servers that LayerZero's verifier relied on. Kelp DAO claims that the attack was a sophisticated state-sponsored attack that compromised two of LayerZero's own servers, which were then used to flood backup servers with junk traffic. The source also contested LayerZero's framing of the '1/1 configuration' as a fringe choice, stating that this setup was actually the default configuration recommended by LayerZero. In fact, 40% of protocols on LayerZero are currently using this same configuration. Security researchers have also questioned LayerZero's account, with some accusing the company of deflecting responsibility for its own compromised infrastructure. Yearn Finance core team developer Artem K reviewed LayerZero's public deployment code and found that the reference setup ships with single-source verification defaults across every major chain. Chainlink community manager Zach Rynes alleged that LayerZero was 'deflecting responsibility' for its own actions and accused the company of throwing Kelp under the bus for trusting a setup that LayerZero itself supported. Kelp DAO has confirmed that the 1-of-1 DVN setup at the center of the incident reflects LayerZero's documented default configuration and has called for a shared and accurate account of what happened in order to make the necessary fixes.