0x51640c985164…51640c9b
KelpDAO Sues LayerZero, Pellegrino Over $292M rsETH Bridge Exploit
KelpDAO has sued LayerZero and co-founder Bryan Pellegrino in British Columbia over the April 18 exploit that drained 116,500 rsETH worth roughly $292 million from its bridge, with Pellegrino calling the claims meritless.
Outputs
116,500 rsETH worth approximately $292 million were drained from KelpDAO's bridge on April 18
The lawsuit was filed in British Columbia through Evercrest Technologies Inc., the entity behind KelpDAO
LayerZero's May incident report traced the intrusion to a March 6 social-engineering attack on a company developer
Co-founder Bryan Pellegrino publicly called the claims 'meritless' and said he will defend the case in Vancouver
Kelp has migrated rsETH cross-chain transfers away from LayerZero's messaging framework pending the litigation
KelpDAO has sued LayerZero and its co-founder Bryan Pellegrino in a British Columbia court over the April 18 exploit that drained 116,500 rsETH, worth approximately $292 million, from the protocol's cross-chain bridge. The civil claim, filed through Evercrest Technologies Inc., the entity behind the Kelp application, marks the first time a major DeFi protocol has formally targeted a cross-chain messaging provider in court over a specific bridge failure.
According to a post from Kelp's official account, the action was brought "to right the wrongs associated with the exploit of rsETH's LayerZero bridge earlier this year." No court has ruled on the allegations. The case now moves through the province's standard civil procedure, which gives defendants a defined window to respond depending on where they were served.
What does KelpDAO allege?
The complaint names LayerZero as a company and Pellegrino personally. KelpDAO claims LayerZero failed to disclose weaknesses embedded in its technology and did not prevent attackers from infiltrating infrastructure tied to its verifier network.
Kelp also asserts that LayerZero reviewed and approved the rsETH bridge's deployment and configuration in writing before the exploit occurred — a point that directly contradicts LayerZero's later position that Kelp's own setup created the vulnerability.
The dispute centers on a configuration known as a 1-of-1 Decentralized Verifier Network, or DVN. LayerZero's April incident statement described Kelp's bridge as running that single-verifier setup, leaving no independent second check capable of catching or rejecting a forged cross-chain message.
The company said it had previously recommended diversifying verifiers and framed the single-DVN configuration as a structural weak point. Kelp has countered that its bridge followed LayerZero's documented defaults and relied on infrastructure that LayerZero itself operated.
How does LayerZero respond?
Pellegrino publicly dismissed the lawsuit, calling the claims "meritless" and stating he will defend himself and LayerZero in Vancouver. He has separately disputed Kelp's account of how the bridge was originally configured, asserting that Kelp used multi-DVN defaults before switching the rsETH deployment to the single-verifier setup that LayerZero later flagged.
LayerZero's May incident report acknowledged that its own infrastructure was breached before the funds moved. According to the report, which traces an investigation cited by Chainalysis, an attacker on March 6 used social engineering against a LayerZero developer to obtain session credentials.
From there, the intruder entered the company's RPC cloud environment and altered internal nodes used by its DVN. During the April 18 attack, those compromised nodes reportedly fed false blockchain data while a denial-of-service strike hit external RPC providers.
The DVN signed the forged message because the information available to it indicated the transaction was valid.
What are the broader stakes?
The case puts a spotlight on how responsibility gets divided when a cross-chain bridge relies on infrastructure operated by a third-party messaging protocol. Two outcomes appear plausible:
- A finding that LayerZero's security lapses drove the loss could reshape how DeFi protocols negotiate liability clauses with bridge providers.
- A finding for LayerZero would reinforce pressure on protocols to adopt multi-verifier setups regardless of provider-recommended defaults.
Security researchers who examined the incident reached mixed conclusions. Some analyses determined that the absence of a second independent verifier allowed the forged message to reach Kelp's Ethereum adapter unchecked. Others focused on how attackers manipulated LayerZero-operated RPC nodes feeding that same verifier. LayerZero has since ended support for 1-of-1 DVN configurations outright.
What happens operationally next?
Kelp has migrated rsETH's cross-chain transfers away from LayerZero's messaging framework toward a different provider and has taken steps to restore full backing and resume normal bridging operations for the token. None of those moves resolve the underlying legal question the suit now puts before a British Columbia court: who bears responsibility when a bridge's security architecture and the infrastructure behind it both come from the same counterparty.
via en.cryptonomist.ch (Original)
More from Elena Vasquez
Show full bio
Staff writer covering marketplaces and e-commerce at Mempool Brief.
438 articles