Kelp DAO Disputes LayerZero's Claim of Responsibility in $290 Million Disaster
A recent cryptocurrency incident has sparked a heated debate, with Kelp DAO and LayerZero pointing fingers at each other over a $290 million disaster. According to sources, Kelp DAO plans to challenge LayerZero's claim that the protocol's single-verifier setup was the primary cause of the exploit. Instead, Kelp DAO asserts that the compromised verifier was part of LayerZero's own infrastructure and that the setup was based on LayerZero's default configuration. The incident occurred when attackers compromised LayerZero's servers, allowing them to drain 116,500 rsETH, worth approximately $290 million, from Kelp's bridge. Kelp DAO claims that LayerZero's own quickstart guide and default GitHub configuration recommend a 1/1 DVN setup, which 40% of protocols on LayerZero currently use. Security researchers have also questioned LayerZero's framing of the incident, with some accusing the company of deflecting responsibility. Yearn Finance core team developer Artem K reviewed LayerZero's public deployment code and found that the reference setup ships with single-source verification defaults across major chains. Chainlink community manager Zach Rynes alleged that LayerZero was deflecting responsibility for its own compromised infrastructure and throwing Kelp under the bus for trusting a setup LayerZero supported. In response, LayerZero has announced that it will no longer sign messages for applications running a single-verifier setup, forcing a protocol-wide migration. Kelp DAO has confirmed that the 1-of-1 DVN setup at the center of the incident reflects LayerZero's documented default configuration and has operated on LayerZero infrastructure since January 2024. The team behind LayerZero is working to harden security across every possible vector for applications.