Kelp said the attack stemmed from a breach of LayerZero’s infrastructure, where attackers compromised the verifier network’s RPC nodes and forced the system to rely on tampered data, allowing fake transactions to be approved.
“After the exploit, LayerZero announced it would no longer sign or attest messages for any application using a 1-1 DVN configuration,” Kelp wrote. “That policy shift, made after hundreds of millions of dollars were exploited, confirms that this was a widely used LayerZero configuration that LayerZero Labs only changed after it failed.”
“That framing does not match the facts,” Kelp DAO wrote. “It is a matter of public domain that this 1-1 setup was not unique to Kelp.”
According to Kelp, it followed LayerZero’s documentation and default configurations. The company also said the setup was widely used across the ecosystem, pointing to data showing a large share of applications relied on similar configurations.
"We're committed to working with the KelpDAO team on improving the cross-chain security of rsETH and supporting their migration to Chainlink CCIP," Chainlink Chief Business Officer Johann Eid told Decrypt. "We have long believed that in order for DeFi to reach its full potential of bringing trillions onchain, the ecosystem needs to be underpinned by highly secure infrastructure."
“There are questions that the ecosystem deserves answers to,” Kelp DAO wrote. “And we are ensuring rsETH is secured by infrastructure that doesn't leave these questions open.”
LayerZero did not immediately respond to a request for comment by Decrypt.



















