Kelp DAO Shifts Blame to LayerZero for $290 Million Disaster, Citing Default Settings

A recent crypto controversy has drawn comparisons to a popular Spiderman meme, with Kelp DAO and LayerZero pointing fingers at each other over a $290 million exploit. According to a source familiar with the matter, Kelp DAO is disputing LayerZero's claim that it ignored warnings about its single-verifier setup. Kelp plans to argue that the compromised verifier was actually part of LayerZero's own infrastructure, and that the setup was based on LayerZero's default configuration. The exploit occurred when attackers drained 116,500 rsETH, worth around $290 million, from Kelp's LayerZero-powered bridge by poisoning the servers that LayerZero's verifier relied on. Kelp claims that the attack was a sophisticated state-sponsored attack that compromised two of LayerZero's own servers, which were then used to flood backup servers with junk traffic. The source also contested LayerZero's claim that Kelp chose a 1-of-1 DVN setup despite recommendations to configure multi-DVN redundancy, pointing out that LayerZero's own quickstart guide and default GitHub configuration recommend a 1/1 DVN setup. In fact, 40% of protocols on LayerZero are currently using the same configuration. Security researchers have also questioned LayerZero's framing of the incident, with one researcher noting that LayerZero's reference setup ships with single-source verification defaults across every major chain. The incident has sparked a wider debate about the security of cross-chain messaging infrastructure, with some accusing LayerZero of deflecting responsibility for its own compromised infrastructure.