Kelp DAO Disputes LayerZero's Account of $290 Million Disaster, Citing Default Settings as Culprit
A recent controversy in the crypto space has sparked a heated debate, with Kelp DAO set to challenge LayerZero's post-mortem analysis of the $290 million exploit that occurred on Sunday. According to a source familiar with the matter, Kelp plans to dispute LayerZero's claim that it ignored repeated warnings to move away from a single-verifier setup. Kelp is a liquid restaking protocol that utilizes user-deposited ether, routing it through a yield-generating system called EigenLayer, and issuing a receipt token, rsETH, in exchange. LayerZero, on the other hand, provides cross-chain messaging infrastructure that moves rsETH between blockchains using entities called DVNs to verify the validity of cross-chain transfers. The recent exploit, which drained 116,500 rsETH worth approximately $290 million from Kelp's LayerZero-powered bridge, has been attributed to a sophisticated state-sponsored attack that compromised LayerZero's own servers. Kelp claims that the compromised DVN was part of LayerZero's infrastructure, not a third-party verifier, and that the setup was based on LayerZero's default configuration. The source contested LayerZero's framing of the '1/1 configuration' as a fringe choice made against guidance, stating that LayerZero's own quickstart guide and default GitHub configuration point to a 1/1 DVN setup, with 40% of protocols on LayerZero currently using the same configuration. Security researchers have also expressed skepticism about LayerZero's isolated framing, which pinned the blame on Kelp. Yearn Finance core team developer Artem K, also known as @banteg on X, posted a technical review of LayerZero's public deployment code, highlighting that the reference setup ships with single-source verification defaults across every major chain. Chainlink community manager Zach Rynes accused LayerZero of deflecting responsibility for its own compromised infrastructure and throwing Kelp under the bus for trusting a setup that LayerZero itself supported. In response, Kelp DAO confirmed that the 1-of-1 DVN setup at the center of the incident reflects LayerZero's documented default configuration, and the team has operated on LayerZero infrastructure since January 2024, maintaining close communication with the LayerZero team. The team behind LayerZero is working to harden security across every possible vector for applications, with co-founder Bryan Pellegrino stating that the initial investigations had been largely resolved and that the team would publish more updates soon.