Kelp DAO Sues LayerZero and CEO Over $292 Million rsETH Bridge Exploit
The operator of liquid restaking protocol Kelp DAO has filed a civil claim in British Columbia, accusing cross-chain provider LayerZero of negligence and infrastructure failures that enabled a $292 million theft.
- Kelp DAO & Evercrest
- Argues that LayerZero approved the bridge configuration and is liable for the infrastructure failure.
- LayerZero & Pellegrino
- Maintains that Kelp DAO ignored diversification recommendations and created a single point of failure.
- Security & Market Analysts
- Focuses on the broader implications for cross-chain infrastructure liability and market migrations.
Perspectives this story doesn't cover
- Retail users who lost funds in the rsETH exploit
- Canadian legal experts on software liability
Why this matters
This lawsuit asks a traditional court to decide who pays when decentralized infrastructure fails—the protocol that configured the security, or the provider whose compromised nodes authorized the theft. The outcome could rewrite liability rules for the entire decentralized finance sector, fundamentally changing how cross-chain bridges are built, insured, and trusted with user funds.
Evercrest Technologies, the operator of liquid restaking protocol Kelp DAO, claims cross-chain infrastructure provider LayerZero approved a single-verifier security setup that allowed attackers to drain 116,500 rsETH—worth $292 million at the time—from its bridge on April 18, 2026. LayerZero and its chief executive, Bryan Pellegrino, counter that Kelp DAO independently downgraded its bridge to a 1-of-1 verification model, creating the single point of failure that permitted a forged message to mint unbacked tokens. The dispute over who bears responsibility for the largest decentralized finance exploit of the year has now moved from technical post-mortems to the Supreme Court of British Columbia.[1][4]
The vulnerability stemmed from how cross-chain bridges confirm transactions between networks. LayerZero operates as a messaging layer, relying on Decentralized Verifier Networks (DVNs) to attest that assets are locked on a source chain before they are released on a destination chain. According to LayerZero's May 2026 incident report, the breach began on March 6 when an attacker—later linked to North Korea's Lazarus Group—socially engineered a LayerZero developer to steal session credentials. This access allowed the attackers to compromise internal remote procedure call (RPC) nodes.[1][4]
On April 18, the compromised nodes fed false blockchain data to the bridge. Because the Kelp DAO bridge to Unichain relied on a single DVN operated by LayerZero, there was no independent secondary verifier to cross-check the data. The lone verifier approved a forged message indicating that 116,500 rsETH had been burned, prompting the Ethereum smart contract to release the equivalent funds. A second attempt to drain an additional 40,000 rsETH, worth roughly $95 million, failed when Kelp DAO paused its contracts 46 minutes after the initial breach.[3][4]
In a civil claim filed on September 24, 2026, Evercrest Technologies accuses LayerZero and Pellegrino of negligence, negligent misrepresentation, and defamation. The lawsuit alleges that LayerZero reviewed and endorsed the 1-of-1 DVN deployment in writing between February 2024 and January 2025. Kelp DAO claims LayerZero explicitly told them there was 'no problem' with the default configuration and even directed them to copy the setup of another single-verifier bridge, while allegedly warning a different developer about the risks of that exact configuration.[1]
In a civil claim filed on September 24, 2026, Evercrest Technologies accuses LayerZero and Pellegrino of negligence, negligent misrepresentation, and defamation.
LayerZero disputes that characterization, maintaining that its standard guidance requires verifier diversification. In public statements following the attack, the company stated that Kelp DAO had initially deployed a multi-DVN setup before manually downgrading to a single verifier. Pellegrino has publicly rejected the lawsuit's premises. "The claim continues to be meritless," Pellegrino wrote in a September 25 statement. "I will meet them in Vancouver and defend myself accordingly."[1][4]
The $292 million loss immediately rippled through the broader decentralized finance ecosystem. The attacker quickly deployed the stolen rsETH as collateral to borrow real assets on lending platforms like Aave, forcing those protocols to absorb significant market stress and estimated bad debt. In the months following the exploit, users withdrew more than $650 million from Kelp DAO's ecosystem, reflecting a sharp decline in confidence.
The technical disagreement has prompted a broader reassessment of cross-chain security models. Following the April incident, Kelp DAO migrated its rsETH bridge infrastructure to Chainlink's Cross-Chain Interoperability Protocol (CCIP). They were not alone; by early August 2026, decentralized finance projects representing approximately $14.5 billion in total value locked had announced similar migrations away from LayerZero's architecture.[4]
The British Columbia lawsuit represents a pivotal test case for liability in decentralized infrastructure. Historically, losses from smart contract exploits or compromised private keys have been treated as assumed risks by users and protocol operators. By pursuing damages in civil court, Evercrest Technologies is asking a traditional legal system to determine the boundary between a software provider's responsibility to secure its own nodes and a client's responsibility to configure redundant safety checks.
Viewpoints in depth
Kelp DAO & Evercrest
The protocol operator argues that LayerZero endorsed the vulnerable setup and failed to secure its own infrastructure.
Evercrest Technologies maintains that the exploit was a failure of LayerZero's internal security, not Kelp DAO's smart contracts. The lawsuit claims that LayerZero explicitly reviewed and approved the 1-of-1 verifier configuration in writing, assuring Kelp DAO that the setup was safe. By failing to disclose the risks of a single point of failure while allegedly warning other developers about the exact same configuration, Kelp DAO argues LayerZero bears liability for the resulting $292 million loss.
LayerZero & Bryan Pellegrino
The infrastructure provider contends that Kelp DAO manually downgraded its security settings against standard recommendations.
LayerZero and its chief executive, Bryan Pellegrino, place the responsibility squarely on Kelp DAO's architectural choices. While acknowledging that attackers compromised LayerZero's internal RPC nodes, the company argues the forged message would have been caught and rejected if Kelp DAO had utilized multiple independent verifiers. LayerZero maintains that its standard guidance advocates for verifier diversification, and that Kelp DAO actively chose to rely on a single verifier, thereby creating the vulnerability that attackers exploited.
Security & Market Analysts
Industry observers view the lawsuit as a critical test of liability for decentralized infrastructure providers.
For the broader decentralized finance sector, the dispute highlights a structural ambiguity in cross-chain architecture: when a protocol relies on a third-party messaging layer, where does the security obligation end? Analysts note that the market has already begun pricing in this risk, evidenced by the $14.5 billion in total value locked that migrated from LayerZero to alternative interoperability protocols like Chainlink's CCIP in the months following the attack. The court's decision could establish a legal precedent for how much responsibility infrastructure providers bear when their compromised systems interact with client-configured security parameters.
Key points
- Kelp DAO's parent company has sued LayerZero and its CEO over a $292 million exploit that occurred on April 18, 2026.
- The lawsuit alleges LayerZero approved a single-verifier bridge setup in writing and failed to secure its internal infrastructure.
- LayerZero contends that Kelp DAO manually downgraded its security configuration, creating the single point of failure that attackers exploited.
- Attackers linked to North Korea compromised LayerZero's internal nodes to forge a message that released 116,500 unbacked rsETH tokens.
- The legal dispute serves as a major test case for liability and security responsibilities in decentralized finance infrastructure.
How we got here
March 6, 2026
An attacker socially engineers a LayerZero developer to steal session credentials and compromise internal RPC nodes.
April 18, 2026
The compromised nodes feed false data to a single verifier, draining 116,500 rsETH worth $292 million from Kelp DAO's bridge.
May 2026
LayerZero publishes an incident report attributing the loss to Kelp DAO's 1-of-1 verifier configuration.
August 2026
Protocols representing $14.5 billion in total value locked announce migrations from LayerZero to alternative infrastructure.
September 24, 2026
Evercrest Technologies files a civil claim against LayerZero and CEO Bryan Pellegrino in British Columbia.
Sources
[1]Unchained CryptoKelp DAO & EvercrestKelp DAO Sues LayerZero and CEO Bryan Pellegrino Over $292 Million rsETH Bridge Exploit
Read on Unchained Crypto →
[2]BinanceLayerZero & PellegrinoKelp DAO Sues LayerZero and Co-Founder Over $292 Million rsETH Exploit
Read on Binance →
[3]Our Crypto TalkKelp DAO & EvercrestKelpDAO LayerZero Lawsuit Targets CEO Over $292M Hack
Read on Our Crypto Talk →
[4]crypto.newsSecurity & Market AnalystsKelpDAO sues LayerZero over $292M rsETH exploit
Read on crypto.news →
Comments
More in Finance
See all →Energy Markets
Brent Crude Surges Past $106 After Houthi Missile Attack on Saudi Aramco Facilities
5 sources
Cloud Infrastructure
Akamai Expands Anthropic Cloud Agreement to $20 Billion, Grants AI Firm 5% Equity Warrant
7 sources
AI Market Watch
Anthropic Pushes $2 Trillion IPO to November, Projects $110 Billion Revenue Run Rate
8 sources
Market Rotation
Stock Market Rally Broadens Beyond Tech as Banks and Small Caps Surge
6 sources
Every angle. Every day.
Get Finance stories with full source coverage and perspective breakdowns delivered to your inbox.




