0x25e0499325e0…25e04996

ConfirmedDeFi581 vB35 sat/vB3 min decode

Kelp DAO Sues LayerZero and CEO Pellegrino Over $292M rsETH Exploit

Kelp DAO has sued LayerZero Labs and CEO Bryan Pellegrino over the April 2024 rsETH exploit, alleging the cross-chain protocol's Endpoint architecture enabled a $292M minting attack on a Layer-2 network.

Kelp DAO Sues LayerZero and CEO Bryan Pellegrino Over $292M rsETH Exploit - CryptoRank
WitnessKelp DAO Sues LayerZero and CEO Bryan Pellegrino Over $292M rsETH Exploit - CryptoRankAI-generated

Outputs

  1. Kelp DAO filed suit against LayerZero Labs and CEO Bryan Pellegrino over the April 2024 rsETH exploit.

  2. The incident left approximately $292 million in rsETH unbacked on a Layer-2 network at the time of the bridge pause.

  3. The attacker exploited a mismatch between two LayerZero endpoint versions to mint rsETH without depositing collateral on Ethereum.

  4. Kelp DAO migrated rsETH to a new, audited mainnet contract after the incident and renounced ownership of the legacy contract.

  5. The complaint's jurisdiction, filing date, and case number were not disclosed in the source item; the matter now moves into discovery.

Kelp DAO has filed suit against cross-chain messaging protocol LayerZero Labs and its chief executive Bryan Pellegrino, alleging that the firm's Endpoint architecture enabled an April 2024 exploit that left approximately $292 million in rsETH unbacked on a Layer-2 network.

The complaint frames LayerZero's messaging layer as the proximate cause of the incident and names the firm's CEO individually, an aggressive posture for a dispute between a DeFi infrastructure vendor and an application built on top of it.

What happened in the April 2024 rsETH exploit?

The incident of April 23, 2024 targeted Kelp DAO's liquid restaking token, an EigenLayer-based derivative the protocol bridges across networks through LayerZero. An attacker exploited a mismatch between two LayerZero endpoint versions: a request on the destination chain referenced an older endpoint that did not enforce the same checks as the version on Ethereum mainnet, letting the attacker mint rsETH on the destination chain without depositing equivalent collateral on Ethereum.

Kelp DAO paused its bridge within minutes and LayerZero shipped an endpoint upgrade to close the version-check gap. The protocol has stated that roughly $292 million in rsETH on the destination chain lacked backing on Ethereum at the time of the pause. Kelp DAO subsequently migrated rsETH to a new, audited mainnet contract and renounced ownership of the legacy contract.

Why name Pellegrino personally?

The decision to add LayerZero's chief executive to the complaint, rather than limit the action to the corporate entity, opens discovery into individual decision-making and communications, and raises the cost of settlement for the defendant. The strategy mirrors moves seen in earlier DeFi disputes, where naming a CEO converts what could be a corporate dispute into a personal-liability question that is harder to ignore.

What is LayerZero's likely defense?

LayerZero has historically characterized its messaging layer as infrastructure that requires application-level security verification, not as a guarantee against application-layer exploits. Other protocols using the same messaging layer were unaffected by the rsETH incident, a fact the protocol is likely to cite in arguing that the vulnerability lay in Kelp DAO's integration rather than in the primitive itself.

What is at stake for cross-chain infrastructure?

The legal theory Kelp DAO advances would, if a court adopted it, treat a cross-chain messaging provider as having assumed duties to the protocols that depend on it. A ruling of that scope would change how omnichain and bridging services are marketed and audited. A narrower ruling turning on the specific representations LayerZero made to Kelp DAO would leave the primitive model intact but expose infrastructure providers to liability for statements made to individual customers.

Either outcome creates a near-term enforcement window in which legal teams at cross-chain infrastructure providers will review their technical documentation and public statements for any language that could be read as a guarantee of downstream security.

What happens next?

The complaint's filing date, jurisdiction, and case number were not disclosed in the source item. The matter will now enter discovery, with both sides exchanging technical documentation of the rsETH bridging architecture, endpoint configurations, and communications around the April 2024 upgrade. LayerZero has not yet issued a public response to the filing.

The dispute crystallizes a question the industry has debated since the incident: when an exploit on a primitive you did not build empties a contract you operate, who pays? The court's eventual answer will travel well beyond these two parties.

via Google News - Crypto Hack Exploit (Source)

More from Daniel Okafor

Daniel Okafor

Show full bio

Correspondent covering industry trends and analytics at Mempool Brief.

435 articles