📈 Get daily crypto insights that make you smarter about your money

KelpDAO Sues LayerZero and Its CEO Over the 292 Million USD rsETH Bridge Exploit

KelpDAO Sues LayerZero and Its CEO Over the 292 Million USD rsETH Bridge Exploit

One of the year’s largest DeFi exploits has officially landed in court. Restaking protocol KelpDAO has filed a lawsuit against cross-chain infrastructure firm LayerZero over the roughly 292 million USD theft of rsETH from its bridge in April, escalating a dispute over responsibility that has simmered for more than five months.

The suit, filed after months of public back-and-forth, also names LayerZero co-founder and CEO Bryan Pellegrino personally. KelpDAO said Friday that LayerZero failed to disclose risks in its technology and failed to prevent attackers from compromising its infrastructure. The protocol further alleged that LayerZero had reviewed and endorsed Kelp’s deployment and configuration in writing before the exploit took place.

“Our number one priority has always been and will remain the security of our users’ assets,” KelpDAO wrote in its statement. “But we also need to correct the record, and hold LayerZero and Mr. Pellegrino accountable for the harm they have caused us and the broader DeFi ecosystem.”

Pellegrino pushed back forcefully, calling the claim “meritless” and saying he would defend the case in Vancouver. Cointelegraph reported that it contacted LayerZero for further comment but had not received a response before publication.

The anatomy of the April 18 attack

The April 18 attack resulted in the theft of 116,500 rsETH, worth about 292 million USD at the time, from Kelp’s LayerZero-powered bridge. In its final incident report, LayerZero said attackers compromised its internal nodes and caused its verifier to approve a forged cross-chain message — effectively tricking the bridge into releasing the restaked tokens.

The critical design question at the heart of both the exploit and the lawsuit is verification redundancy. LayerZero argued that the loss was possible because Kelp’s bridge relied on a single LayerZero decentralized verifier network, or DVN, as its only verification path. With no second independent verifier required, the bridge released the rsETH after LayerZero’s own verifier approved the forged message. LayerZero said it had recommended using multiple DVNs and subsequently stopped acting as the sole required verifier for applications built on its stack.

Kelp has told a different story since the earliest days of the fallout. In May, the protocol said its DVN configuration had previously been discussed with LayerZero and “confirmed as secure,” and it accused the infrastructure firm of failing to adequately warn it about the risks of the setup.

A migration already in motion

Regardless of how the court battle unfolds, KelpDAO has already moved to reduce its dependence on the disputed architecture. The protocol announced plans to migrate the rsETH bridge to Chainlink’s Cross-Chain Interoperability Protocol, a shift that would place verification in the hands of a different set of operators and standards.

The migration underscores a broader lesson for DeFi teams building on cross-chain infrastructure: the security assumptions of a bridge are only as strong as its verification path. When a single verifier can authorize the release of hundreds of millions of dollars in assets, the compromise of one party’s internal systems becomes a systemic event rather than an isolated incident.

Why the case matters beyond KelpDAO

The lawsuit is significant for the DeFi sector because it tests a question that courts have rarely addressed directly: when a protocol is exploited through a third party’s infrastructure, who bears the loss? LayerZero’s position places responsibility on applications for choosing their own security configurations, while Kelp’s position places responsibility on the infrastructure provider for endorsing that configuration and for the integrity of its own systems.

A protracted legal fight in Vancouver could set precedent for how infrastructure providers disclose risk, how they review client deployments, and what “endorsement” means in writing before an exploit. For the many protocols that bridged billions of dollars through LayerZero-powered stacks during the cross-chain boom, those questions are not hypothetical.

Recovery prospects, meanwhile, have remained dim. Reporting earlier this year tracked the Kelp DAO hacker laundering the large majority of the roughly 220 million USD in traceable stolen funds, leaving victims with little recourse outside legal and insurance channels — which is precisely what this lawsuit now represents.

Neither side has signaled willingness to settle. What began as an April exploit has now become one of the most consequential accountability battles in decentralized finance this year, with the outcome likely to echo through every protocol that depends on someone else’s pipes.

Market snapshot at press time (Sept. 27, 2026, 13:50 UTC): ETH at 2,705.03 USD, up 0.75 percent in 24 hours; BTC at 84,859 USD, up 1.09 percent; SOL at 122.89 USD, up 1.85 percent.

16 thoughts on “KelpDAO Sues LayerZero and Its CEO Over the 292 Million USD rsETH Bridge Exploit”

    1. ^ and they only said they recommended multiple DVNs after the fact. reads like they knew single verifier setups were fragile before April 18

  1. 292M gone and the DVN config was supposedly confirmed as secure in writing? if that email actually exists this case is a wrap

    1. the whole thing hinges on who signed off on the DVN setup. kelp says layerzero confirmed it in writing, layerzero says it was the default config. one of them is lying

      1. the whole case lives or dies on that written sign-off. discovery on the internal slack logs is gonna be brutal for whoever is bluffing

      2. if the endorsement email exists its production ready evidence, no forensic interpretation needed. if it doesnt, kelp just torched their credibility in vancouver

  2. Naming Pellegrino personally is the interesting part. The corporate shield usually absorbs these things. Vancouver court is gonna be messy

  3. LayerZero reviewed the config in writing, then blamed Kelp for trusting their own review. Both things can be true, but that written endorsement is going to sting in a Vancouver courtroom.

    1. genuine question, kelp is migrating the bridge to CCIP anyway. at that point is the suit mostly a damages claim for the april loss?

    1. Or their lawyers spent five months making sure the complaint survives a motion to dismiss. You dont rush a 292M claim against a company with LayerZeros legal budget.

  4. 220 of 292 million already laundered and the two sides are arguing over who apologizes. lawyers will eat whatever is left

    1. recovered funds attach to the judgment too, whatever the CCIP migration saves could still flow back to users. assuming anyone wins

  5. calling it meritless within hours of being named personally is wild confidence for a guy whose team allegedly greenlit the config in writing. save it for the Vancouver courtroom

Leave a Comment

Your email address will not be published. Required fields are marked *

BTC$84,437.00+0.4%ETH$2,690.49-0.1%SOL$121.71-0.1%BNB$774.35+0.0%XRP$1.51-2.4%ADA$0.2539-2.4%DOGE$0.0968-1.8%DOT$1.23-4.0%AVAX$11.02+0.3%LINK$14.09-1.1%UNI$9.63-0.9%ATOM$1.86-0.8%LTC$71.12-2.5%ARB$0.2213-3.6%NEAR$5.19+7.2%FIL$1.14-5.1%SUI$1.23+4.3%BTC$84,437.00+0.4%ETH$2,690.49-0.1%SOL$121.71-0.1%BNB$774.35+0.0%XRP$1.51-2.4%ADA$0.2539-2.4%DOGE$0.0968-1.8%DOT$1.23-4.0%AVAX$11.02+0.3%LINK$14.09-1.1%UNI$9.63-0.9%ATOM$1.86-0.8%LTC$71.12-2.5%ARB$0.2213-3.6%NEAR$5.19+7.2%FIL$1.14-5.1%SUI$1.23+4.3%
Scroll to Top