Kelp DAO Challenges LayerZero's Account of $290 Million Disaster, Citing Default Settings as Culprit
A recent crypto controversy has drawn comparisons to a popular meme, with Kelp DAO set to dispute LayerZero's assessment of the $290 million exploit that occurred on Sunday. According to a source familiar with the matter, Kelp plans to argue that the compromised verifier was actually part of LayerZero's own infrastructure, rather than a third-party verifier. The incident involved the draining of 116,500 rsETH, worth approximately $290 million, from Kelp's LayerZero-powered bridge. Kelp claims that the attack was a sophisticated state-sponsored attack that compromised two of LayerZero's servers, which were then used to flood backup servers with junk traffic. The source contested LayerZero's characterization of the '1/1 configuration' as a fringe choice made against guidance, pointing out that LayerZero's own quickstart guide and default GitHub configuration recommend a 1/1 DVN setup. In fact, 40% of protocols on LayerZero are currently using this configuration. Kelp's core restaking contracts were not affected, and the exploit was isolated to the bridge layer. Security researchers have also questioned LayerZero's account, with one developer noting that LayerZero's reference setup ships with single-source verification defaults across every major chain. The incident has led to a protocol-wide migration, with LayerZero announcing that it will no longer sign messages for any application running a single-verifier setup.