#LayerZeroCEOAdmitsProtocolFlaws


In a significant turnaround, LayerZero Labs CEO Bryan Pellegrino has publicly admitted protocol failures following the $292 million hack of Kelp DAO on April 18, 2026, where an attacker exploited a 1/1 security configuration to steal rsETH tokens.

Publishing his statement on X (formerly Twitter) on May 4, 2026, Pellegrino confessed that the LayerZero protocol failed to prevent or flag the hazardous 1/1 configuration. He acknowledged he "wrongly assumed no application would secure billions in TVL on such a configuration". Additionally, Pellegrino admitted that LayerZero further worsened the crisis by enforcing RPC quorum changes without notifying affected clients, calling their communication "a complete failure". He concluded by pledging that the company would fully refocus on serving asset issuers and the upcoming launch of Zero.

This admission marked a dramatic reversal from LayerZero's initial response, which placed the blame squarely on the application layer and Kelp DAO's own configuration choices. The public apology followed extensive criticisms from the crypto community, particularly after third-party developers demonstrated how the dangerous 1/1 configuration was featured prominently in LayerZero's official documentation as a starting point. The shift in sentiment eventually forced Pellegrino to take responsibility for what critics termed "systemic arrogance".

Kelp DAO, however, remains unconvinced. On May 5, they published a detailed rebuttal arguing the compromised configuration was the platform's standard, claiming that roughly 47% of LayerZero's 2,665 active contracts ran on 1/1 setups at the time of the exploit. Kelp also released telegram screenshots allegedly showing a LayerZero employee approving the 1/1 configuration prior to the incident. Kelp further questioned why LayerZero's monitoring failed to detect the RPC node compromise before the forged messages were signed, a breach they tie directly to North Korea's Lazarus Group.
Consequently, Kelp DAO has confirmed its migration of rsETH from LayerZero to Chainlink's CCIP standard across all supported chains, underscoring the permanent loss of trust in the protocol's architecture.

#LayerZero #KelpDAO #CryptoHack #DeFi
ZRO-1.32%
LINK3.07%
post-image
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pin