Kelp DAO Disputes LayerZero's Account of $290 Million Exploit, Citing Default Settings as Culprit
A recent $290 million disaster has sparked a heated debate between Kelp DAO and LayerZero, with Kelp set to challenge LayerZero's post-mortem analysis of the incident. According to a source familiar with the matter, Kelp plans to argue that the compromised verifier was part of LayerZero's own infrastructure, rather than a third-party verifier. The incident occurred when attackers drained 116,500 rsETH, worth approximately $290 million, from Kelp's LayerZero-powered bridge by poisoning the servers that LayerZero's verifier relied on to validate transactions. Kelp claims that the attackers compromised two of LayerZero's own servers, which were used to check the legitimacy of cross-chain transactions, and then flooded the backup servers with junk traffic to force LayerZero's verifier onto the compromised ones. The source also contested LayerZero's claim that Kelp chose a 1-of-1 DVN setup despite recommendations to configure multi-DVN redundancy, stating that LayerZero's own quickstart guide and default GitHub configuration point to a 1/1 DVN setup. Kelp's core restaking contracts were not affected, and the exploit was isolated to the bridge layer. The incident has raised questions about the security of cross-chain messaging infrastructure and the responsibility of protocols to ensure the safety of user funds. Security researchers have also weighed in on the debate, with some accusing LayerZero of deflecting responsibility for its own compromised infrastructure. Yearn Finance core team developer Artem K noted that LayerZero's reference setup ships with single-source verification defaults across every major chain, which can leave protocols vulnerable to attacks. Chainlink community manager Zach Rynes alleged that LayerZero was deflecting responsibility for its own compromised infrastructure and accused the company of throwing Kelp under the bus for trusting a setup that LayerZero itself supported.