0x27d7d0a327d7…27d7d0a0
LayerZero Faces $292M Vendor-Liability Suit From Kelp DAO in Vancouver
Kelp DAO sued LayerZero Labs and co-founder Bryan Pellegrino in British Columbia court on September 25, 2026, seeking damages over a $292M exploit that drained 116,500 rsETH on April 18, 2026.
Outputs
116,500 rsETH worth approximately $292 million was minted without backing on Ethereum mainnet on April 18, 2026, roughly 18% of circulating supply.
Evercrest Technologies filed the claim in the Supreme Court of British Columbia on September 25, 2026, against LayerZero Labs Ltd., LayerZero Labs Canada Inc., and co-founder Bryan Pellegrino.
Mandiant and CrowdStrike attributed the attack to TraderTraitor (UNC4899), linked to North Korea's Lazarus organization, per LayerZero's incident report.
Aave saw roughly $6.6 billion in TVL pulled in the days after the hack, per Galaxy Research.
Kelp alleges negligence, negligent misrepresentation, and defamation, including claims LayerZero approved in writing the single-verifier configuration it later blamed.
Evercrest Technologies, the entity behind liquid restaking protocol Kelp DAO, filed a civil claim on September 25, 2026 in the Supreme Court of British Columbia seeking damages, aggravated damages, and punitive damages from LayerZero Labs Ltd., LayerZero Labs Canada Inc., and co-founder Bryan Pellegrino over a $292 million exploit on Kelp's rsETH bridge.
The lawsuit, filed nearly five months after the April 18, 2026 attack drained 116,500 rsETH, marks a departure from typical DeFi hack litigation. Where prior cases, including Mango Markets, Euler Finance, and Platypus, centered on chasing the alleged attacker, Kelp's claim targets the infrastructure vendor and a named executive directly.
How the $292M Loss Happened
At 17:35 UTC on April 18, an attacker minted 116,500 rsETH on Ethereum mainnet with no legitimate backing. The haul represented roughly 18% of rsETH's circulating supply, approximately 630,000 tokens at the time, according to DeFiPrime.
The exploit was not a smart contract bug. LayerZero's incident report traces the attack to a social engineering campaign launched on March 6 against one of its developers. Session keys obtained through that phishing gave the attacker entry into LayerZero's cloud and RPC infrastructure. Internal nodes were compromised and patched in memory, fooling monitoring tools.
When an external RPC provider was knocked offline, the Decentralized Verifier Network's signing service fell back on the two compromised nodes, which produced a valid-looking attestation for a forged cross-chain message. Kelp's bridge, configured with a single verifier rather than a multi-party quorum, released the rsETH without a second check.
Mandiant and CrowdStrike, cited in LayerZero's report, attributed the operation to TraderTraitor (UNC4899), a group linked to North Korea's Lazarus organization.
What Does Kelp Actually Allege?
The notice of civil claim raises three causes of action: negligence, negligent misrepresentation, and defamation. The first two center on Kelp's assertion that LayerZero reviewed and approved in writing the single-verifier bridge configuration it later blamed for the loss. If that approval holds as evidence, the case turns from a question about whose code failed into a question about who signed off on the design before it failed.
Kelp framed the lawsuit publicly the same day it filed. "Today we filed a lawsuit against LayerZero and its co-founder, Bryan Pellegrino, to right the wrongs associated with the exploit of rsETH's LayerZero bridge earlier this year," Kelp DAO wrote on X.
The protocol expanded its theory of the case in the same thread: "As alleged in our lawsuit, the exploit was a direct result of LayerZero's failures — including a failure to disclose weaknesses and risks inherent in LayerZero's own technology, and a failure to prevent an infiltration of LayerZero's own security infrastructure, which allowed attackers to exploit those weaknesses."
The defamation claim targets statements Pellegrino reportedly made on Telegram and X pinning blame on Kelp's configuration choices. By naming the co-founder personally, Kelp is testing whether executive commentary during an active incident creates separate legal exposure.
What Comes Next in the Proceeding
Neither party has published the full claim or filed a formal response. Civil cases in British Columbia typically allow defendants a fixed response window before discovery, where both sides exchange documents, potentially including the written approval at the center of the misrepresentation claim.
Cases of this size in Canadian courts commonly run one to three years to trial if not settled first. The personal defamation claim against Pellegrino may accelerate settlement pressure, since executives typically seek faster resolution on claims tied to their name than those hitting only the corporate entity.
How Far Did the Damage Spread?
The exploit's second-order effects extended well past the direct $292 million loss. Because rsETH served as collateral across multiple lending markets, de-risking rippled immediately after the hack. Galaxy Research's writeup estimated roughly $6.6 billion in TVL was pulled from Aave alone in the days following.
Kelp says it has begun migrating rsETH's bridge to a multi-verifier cross-chain security standard, though that migration was still underway five months after the exploit. The protocol added in its X statement: "Since the exploit, we have taken action to ensure our users' assets are secure, including by undertaking the migration of rsETH's bridge to a more secure cross-chain security standard."
For interoperability vendors operating in a market that includes Wormhole, Axelar, and Chainlink's CCIP, the lawsuit puts a specific allegation on the record: that LayerZero approved in writing the exact configuration it later blamed for a nine-figure loss. Protocol teams evaluating cross-chain messaging vendors will now weigh that allegation during due diligence, regardless of whether the British Columbia court reaches the merits.
via shattered.io (Original)