Fri. Sep 25th, 2026

KelpDAO Sues LayerZero and Bryan Pellegrino Over $292M rsETH Exploit

ByJohan Shamshad

September 25, 2026 #KelpDAO
HackHack

KelpDAO has escalated its months-long dispute with LayerZero into court, filing a civil claim against the cross-chain infrastructure provider and its co-founder and CEO Bryan Pellegrino over the April exploit that resulted in the loss of roughly $292 million in rsETH.

Kelp announced the lawsuit on September 25. The action was filed in British Columbia through Evercrest Technologies Inc., the entity associated with KelpDAO, and names both LayerZero and Pellegrino as defendants.

The case stems from the April 18 attack on KelpDAO’s rsETH bridge, when an attacker caused 116,500 rsETH to be released on Ethereum without a corresponding legitimate transaction on the source chain. The tokens were worth approximately $292 million at the time.

Kelp alleges that LayerZero failed to adequately disclose weaknesses and risks in its technology, failed to prevent attackers from compromising security infrastructure supporting the bridge, and had previously reviewed and approved Kelp’s deployment and configuration in writing.

Pellegrino disputes the allegations. He has described the claim as “meritless” and said he intends to defend himself and LayerZero in Vancouver. No court has ruled on Kelp’s allegations, and the filing marks the beginning of the legal dispute rather than a determination of liability.

The April Attack Compromised LayerZero Infrastructure

The technical sequence behind the exploit is unusually important because the dispute is not centered on a conventional smart-contract bug.

LayerZero’s final incident report said the intrusion began on March 6, when an attacker socially engineered a LayerZero Labs developer, obtained session credentials and gained access to the company’s RPC cloud environment. Internal RPC nodes were then manipulated so they could provide fraudulent blockchain data to LayerZero Labs’ Decentralized Verifier Network, or DVN.

The attacker also launched a denial-of-service attack against an external RPC provider. That forced the LayerZero Labs DVN to rely on the compromised internal nodes, which ultimately caused it to produce a valid attestation for a cross-chain message that should not have existed.

Because Kelp’s bridge was using a single-verifier configuration, no second independent DVN was required to reject that message. The destination contract therefore accepted the attestation and released 116,500 rsETH.

An independent Chainalysis analysis similarly concluded that the incident involved compromised off-chain infrastructure rather than a conventional smart-contract exploit. The blockchain contracts processed what appeared to be a valid message even though the underlying view of the source chain had been falsified.

That distinction has become increasingly important across decentralized finance. Recent incidents such as Payy’s $1.83 million USDC bridge exploit have again shown how a failure in infrastructure responsible for validating withdrawals can affect an entire product even when the visible on-chain transaction executes normally.

LayerZero Later Acknowledged a Security Mistake

The disagreement over responsibility began almost immediately after the attack.

LayerZero initially emphasized Kelp’s use of a 1-of-1 DVN configuration, arguing that an independent additional verifier could have prevented the compromised LayerZero Labs DVN from authorizing the fraudulent transaction.

Kelp pushed back, saying its configuration had been reviewed by LayerZero personnel and was consistent with practices used elsewhere in the ecosystem.

LayerZero subsequently changed its public position. In May, the company acknowledged that it had made a mistake by allowing its DVN to serve as the sole required verifier for high-value transfers and said it had failed to adequately police what its verifier was securing.

That statement did not amount to an admission of legal liability for Kelp’s losses. It did, however, acknowledge that LayerZero’s own operational decisions contributed to the security model that existed when the exploit occurred.

LayerZero later rebuilt the affected operational infrastructure and changed its policy so that its DVN would no longer participate as the sole required attestor on a channel.

Kelp, meanwhile, moved rsETH away from LayerZero and toward Chainlink CCIP. The decision came as security assumptions around crosschain infrastructure were becoming more important as assets and liquidity increasingly spread across multiple networks.

The Lawsuit Could Test Who Owns Cross-Chain Security Risk

The most interesting part of this case is not simply who operated the compromised servers. It is where responsibility begins and ends when several organizations collectively create a security system.

LayerZero can point to the application-level configuration: Kelp’s bridge required only one DVN. Kelp can point to the infrastructure underneath that verifier, which LayerZero itself says was compromised, as well as its allegation that LayerZero personnel reviewed and approved the configuration.

Those facts create a much harder question than a normal software vulnerability.

If a protocol technically allows customers to choose their own security model, how much responsibility does the infrastructure provider have when it knows its own service is being used as the only line of defense? And if that provider reviews or approves the deployment, does that create additional responsibility for the resulting security assumptions?

Discovery could therefore be more important than the initial complaint. Internal messages, integration discussions, security recommendations, documentation and risk warnings could establish what each side actually knew before the attack.

Investors Should Watch the Commercial Fallout as Closely as the Court Case

For LayerZero, the immediate financial consequence of the lawsuit is only one part of the risk.

Cross-chain infrastructure depends heavily on trust from protocols deciding where to move potentially billions of dollars in assets. A prolonged legal dispute that focuses on infrastructure security, configuration advice and responsibility for integration decisions could influence how developers evaluate providers even before a court reaches a conclusion.

This is especially relevant because cross-chain failures can spread well beyond the original bridge. The Kelp attacker was able to move rsETH into lending markets and borrow other assets against it, demonstrating how one infrastructure failure can create liabilities elsewhere in DeFi.

Similar contagion mechanics have appeared in other incidents. The Nomic exploit left Osmosis’s allBTC underbacked after counterfeit bridged Bitcoin entered a downstream asset, while a separate SingularityNET bridge compromise spread across multiple connected projects.

That is why the KelpDAO lawsuit could matter beyond the $292 million figure attached to the original exploit.

DeFi increasingly depends on infrastructure that users rarely see: RPC providers, verifiers, bridges, signing systems, privileged keys and cross-chain messaging networks. When those layers fail, determining responsibility can be far less straightforward than identifying the transaction that moved the money.

The court case may ultimately provide a clearer answer to a question crypto infrastructure has largely dealt with through technical documentation rather than legal precedent: when several parties jointly build a security model and one layer fails catastrophically, who is responsible for the risk that everyone else relied on?

For LayerZero and KelpDAO, that question has moved from post-mortems and public statements into a courtroom.

Financial Markets Analyst and Journalist at  |  More Posts

Johan Shamshad is a financial markets writer at Dave Finances covering cryptocurrencies, trading platforms, brokers, fintech, financial regulation, and developments across global markets. He previously worked at Gulf News, adding newsroom experience to his coverage of fast-moving financial and digital-asset markets.

His work focuses on identifying market-moving events, company developments, regulatory changes, product launches, and shifts in trading and financial infrastructure.

Johan contributes news and analysis designed to help readers understand not only what happened, but why a development matters and how it may affect the wider financial landscape.

Leave a Reply

Your email address will not be published. Required fields are marked *