Kelp DAO Blames LayerZero's Default Settings for $290 Million Disaster
A recent exploit resulted in the loss of $290 million from Kelp DAO, a liquid restaking protocol, with the company now set to dispute LayerZero's post-mortem of the incident. According to a source familiar with the matter, Kelp DAO plans to argue that the compromised verifier was part of LayerZero's own infrastructure, not a third-party verifier, and that the setup it was using was LayerZero's default configuration. The incident occurred when attackers drained 116,500 rsETH, worth about $290 million, from Kelp's LayerZero-powered bridge by poisoning the servers that LayerZero's verifier relied on to check transactions. Kelp DAO claims that the attackers compromised two of LayerZero's own servers and then flooded the backup servers with junk traffic to force LayerZero's verifier onto the compromised ones. The source also contested LayerZero's claim that KelpDAO chose a 1-of-1 DVN setup despite recommendations to configure multi-DVN redundancy, stating that LayerZero's own quickstart guide and default GitHub configuration point to a 1/1 DVN setup. Security researchers have also questioned LayerZero's framing of the incident, with one researcher noting that LayerZero's reference setup ships with single-source verification defaults across every major chain. Kelp DAO has stated that it has operated on LayerZero infrastructure since January 2024 and maintained close communication with the LayerZero team, and that the 1-of-1 DVN setup at the center of the incident reflects LayerZero’s documented default configuration.