Kelp DAO is challenging layerzero‘s account of a $290 million rsETH bridge exploit, arguing the failure came from the platform’s own defaults, not an unusual setupKelp DAO is challenging layerzero‘s account of a $290 million rsETH bridge exploit, arguing the failure came from the platform’s own defaults, not an unusual setup

LayerZero dispute deepens after $290 million rsETH bridge drain

2026/04/20 23:15
3분 읽기
이 콘텐츠에 대한 의견이나 우려 사항이 있으시면 crypto.news@mexc.com으로 연락주시기 바랍니다
layerzero

Kelp DAO is challenging layerzero‘s account of a $290 million rsETH bridge exploit, arguing the failure came from the platform’s own defaults, not an unusual setup. The dispute now centers on who controlled the keys, the code, and the warnings.

What happened in the exploit

On Saturday, attackers drained 116,500 rsETH, worth about $290 million, from Kelp’s LayerZero-powered bridge after poisoning the servers used to verify transfers. The attack did not touch Kelp’s core restaking contracts, and the emergency pause came 46 minutes later.

That pause blocked two follow-up attempts that would have released an additional ~$200 million in rsETH. Moreover, the source familiar with Kelp’s response said the breach stayed limited to the bridge layer.

How Kelp says the setup worked

Kelp plans to argue that the compromised DVN was LayerZero’s own infrastructure, not a third-party verifier chosen by the protocol. The memo reviewed by CoinDesk says the attack used LayerZero servers that checked whether cross-chain transactions were legitimate.

However, Kelp’s source said the backup servers were flooded with junk traffic, which pushed the verifier onto the compromised nodes. All of that infrastructure was built and run by LayerZero, the source said.

The protocol also disputes the claim that it ignored guidance to move away from a single verifier setup. Through a direct communications channel open since July 2024, Kelp says it received no specific recommendation to change the rsETH DVN configuration.

Why the configuration is under scrutiny

LayerZero’s post-mortem said KelpDAO chose a 1-of-1 DVN setup despite recommendations to use multi-DVN redundancy. In practice, a 1/1 configuration means one validator can approve a cross-chain message alone, while multi-validator setups reduce single-point failure risk.

Moreover, Kelp’s source said LayerZero’s own quickstart guide and default GitHub configuration point to the same 1/1 structure. The source added that 40% of protocols on LayerZero are currently using that setup.

The same configuration appears in LayerZero’s V2 OApp Quickstart, where the sample layerzero.config.ts assigns one required DVN and no optional DVNs. That is the exact model Kelp says it followed.

Critics say the blame is misplaced

Security researchers are also pushing back. Yearn Finance core team developer Artem K, known on X as @banteg, said LayerZero’s public deployment code uses single-source verification defaults across Ethereum, BSC, Polygon, Arbitrum and Optimism.

He also noted that the deployment leaves a public endpoint exposed, which leaks the list of configured servers to anyone who queries it. That said, he said he cannot prove which configuration Kelp used.

Chainlink community manager Zach Rynes was sharper on X, accusing LayerZero of deflecting responsibility and throwing Kelp under the bus for trusting a setup LayerZero itself supported. He said the company was trying to shift blame for its own compromised infrastructure.

CoinDesk said it reached out to LayerZero for comment and had not heard back by publication. Meanwhile, LayerZero has vowed to stop signing messages for any application using a single-verifier setup, which will force a broader migration across its network.

In the end, the fight over this layerzero incident is no longer just about one bridge. It has become a test of documentation, defaults and accountability in cross-chain security.

시장 기회
Notcoin 로고
Notcoin 가격(NOT)
$0.0004466
$0.0004466$0.0004466
+7.66%
USD
Notcoin (NOT) 실시간 가격 차트
면책 조항: 본 사이트에 재게시된 글들은 공개 플랫폼에서 가져온 것으로 정보 제공 목적으로만 제공됩니다. 이는 반드시 MEXC의 견해를 반영하는 것은 아닙니다. 모든 권리는 원저자에게 있습니다. 제3자의 권리를 침해하는 콘텐츠가 있다고 판단될 경우, crypto.news@mexc.com으로 연락하여 삭제 요청을 해주시기 바랍니다. MEXC는 콘텐츠의 정확성, 완전성 또는 시의적절성에 대해 어떠한 보증도 하지 않으며, 제공된 정보에 기반하여 취해진 어떠한 조치에 대해서도 책임을 지지 않습니다. 본 콘텐츠는 금융, 법률 또는 기타 전문적인 조언을 구성하지 않으며, MEXC의 추천이나 보증으로 간주되어서는 안 됩니다.

Roll the Dice & Win Up to 1 BTC

Roll the Dice & Win Up to 1 BTCRoll the Dice & Win Up to 1 BTC

Invite friends & share 500,000 USDT!