In an incident involving the Kelp DAO rsETH bridge, $292 million worth of cryptocurrency was withdrawn due to a security breach. This event has sparked a wave of mutual accusations between Kelp DAO and LayerZero over who was responsible for the vulnerability. While LayerZero argued that Kelp DAO’s use of a single validator setup created the risk, Kelp DAO countered by claiming that LayerZero’s team had approved this configuration, igniting a heated debate in the crypto community.
Approval dispute and internal communications
LayerZero is recognized in the crypto ecosystem as a platform that develops infrastructure enabling cross-chain communication for decentralized applications. On the other hand, Kelp DAO operates as a decentralized autonomous organization managing an Ethereum-based rsETH bridge. According to new documentation released by Kelp DAO, the LayerZero team reviewed Kelp’s one-to-one validator setup over two and a half years across eight separate integration meetings, yet never raised security concerns. Shared screenshots suggest that the LayerZero team left the decision on validator configuration up to Kelp and implied that switching to a private validator was not mandatory. However, it remains unclear whether these messages have been independently verified.
Kelp DAO further highlighted that LayerZero’s official bug bounty documentation expressly excludes misconfigurations on the application side from eligibility and noted that the majority of official examples demonstrate the single validator (DVN) model.