Kelp DAO Disputes LayerZero's Account of $290 Million Exploit, Claims Default Settings Were to Blame
A recent crypto incident has sparked a heated debate, with Kelp DAO and LayerZero at the center. The liquid restaking protocol is pushing back against LayerZero's post-mortem of the $290 million exploit, which occurred on Sunday. According to a source familiar with the matter, Kelp plans to dispute LayerZero's claim that it ignored repeated warnings to move away from a single-verifier setup. The issue began when attackers drained 116,500 rsETH, worth approximately $290 million, from Kelp's LayerZero-powered bridge by poisoning the servers that LayerZero's verifier relied on to check transactions. Kelp claims that the compromised verifier was part of LayerZero's own infrastructure, not a third-party verifier, and that the setup was based on LayerZero's default onboarding configuration. The source contested LayerZero's framing of the '1/1 configuration' as a fringe choice made against guidance, stating that LayerZero's own quickstart guide and default GitHub configuration point to a 1/1 DVN setup. Security researchers have also questioned LayerZero's isolated framing, which pinned the blame on Kelp. Yearn Finance core team developer Artem K posted a technical review of LayerZero's public deployment code, highlighting that the reference setup ships with single-source verification defaults across every major chain. Chainlink community manager Zach Rynes accused LayerZero of 'deflecting responsibility' for its own compromised infrastructure and throwing Kelp under the bus for trusting a setup LayerZero itself supported. In response, LayerZero has stated that it will no longer sign messages for any application running a single-verifier setup, forcing a protocol-wide migration. Kelp DAO has confirmed that the 1-of-1 DVN setup at the center of the incident reflects LayerZero’s documented default configuration and has called for a shared and accurate account of what happened to make the necessary fixes.