$290 Million Exploit Renews Scrutiny on DeFi Bridge Security
LayerZero Labs has responded to the roughly $290 million rsETH exploit tied to KelpDAO, arguing that the incident was not caused by a direct failure of the core protocol but by a compromise at the downstream remote procedure call, or RPC, infrastructure layer. According to the company, the attackers allegedly manipulated RPC systems used by the decentralized verifier network, fed distorted data to verifiers, and launched distributed denial-of-service attacks against uncompromised endpoints, allowing fraudulent transactions to be validated while avoiding detection.
LayerZero said the main weakness was KelpDAO’s single-DVN 1:1 configuration for rsETH. Under that setup, once the supporting infrastructure was compromised, there was no independent verifier left to reject forged messages. The company argued that this deployment ran against its long-standing recommendation for Multi-DVN redundancy. With a diversified verifier setup, it said, consensus across multiple parties would have made the exploit ineffective even if one path had been breached.
Claims of No Wider Impact Face Pushback
In its statement, LayerZero said it reviewed active integrations across the protocol and could “confidently confirm that no other assets or applications were impacted.” The company framed the loss as fully isolated to KelpDAO’s rsETH integration, presenting the outcome as evidence that its modular security design prevented broader contagion across the ecosystem.
That interpretation has been challenged by parts of the crypto community. Chainlink community liaison Zach Rynes argued that LayerZero was shifting blame away from the compromise of its own DVN node infrastructure. In his view, the deeper issue lies in concentrated control over both infrastructure and validation, creating a single point of failure. He also rejected the emphasis on “no contagion” as an insufficient defense against the structural risks of centralized validator models.
Responsibility and Bridge Design Back in Focus
The episode has sharpened a broader debate over accountability in crypto infrastructure. When one system influences both verification logic and the infrastructure beneath it, it remains unclear whether responsibility should fall on the protocol provider, the integrating application, or both. At the same time, KelpDAO is now under pressure to adopt a Multi-DVN configuration, a move that many observers see as a sign that security expectations for cross-chain systems are tightening.
Related reporting also noted that the rsETH exploit affected funds on Ethereum and Arbitrum and left Aave V3 dealing with significant bad debt exposure. As more details emerge, scrutiny of bridge validator design, infrastructure redundancy, and the true level of decentralization in DeFi is likely to intensify.

