KelpDAO has sued LayerZero and co-founder and CEO Bryan Pellegrino in British Columbia over the April 18 rsETH exploit that drained 116, 500 rsETH, worth about $292 million at the time. The case is now about more than one bad day in DeFi. It is a fight over who owned the risk, who approved the setup, and who gets stuck with the bill when cross-chain verification goes sideways.
- Lawsuit filed: Evercrest Technologies Inc., the legal entity behind Kelp, is suing LayerZero and Bryan Pellegrino in British Columbia.
- What was drained: 116, 500 rsETH, worth about $292 million.
- Main dispute: Kelp blames LayerZero’s infrastructure and disclosures; LayerZero blames Kelp’s 1-of-1 verifier setup.
- Why it matters: The case could shape how DeFi courts assign liability when bridge verification fails.
The core technical issue is simple, even if the plumbing is not: LayerZero says Kelp used a 1-of-1 Decentralized Verifier Network, or DVN. That means a single verifier could authorize the cross-chain message. In plain English, one compromised checkpoint was enough to let attackers push through a fake transfer. That is not “decentralized” in any meaningful sense. It is a single point of failure wearing a nice suit.
Kelp’s position is that LayerZero failed to disclose weaknesses and risks in its technology and failed to stop attackers from penetrating the security infrastructure used by its verifier. LayerZero’s version is the opposite. It says Kelp chose the risky configuration and LayerZero had already recommended verifier diversification.
LayerZero published its incident report in May and said the intrusion began on March 6, when an attacker socially engineered a LayerZero developer and obtained session credentials. From there, LayerZero says the attacker entered its RPC cloud environment and altered internal RPC nodes used by the LayerZero Labs DVN. On April 18, according to LayerZero’s account, compromised nodes supplied false blockchain data, external RPC providers were hit with a denial-of-service attack, and the DVN signed a forged message.
That forged message reportedly caused Kelp’s Ethereum bridge flow to release 116, 500 rsETH even though no matching burn had happened on the source chain. A second attempt reportedly sought another 40, 000 rsETH, worth roughly $95 million to $100 million at the time, but Kelp paused its contracts before that forged packet could execute. The pause came about 46 minutes after the successful drain.
Chainalysis described the event as an attack on off-chain verification infrastructure, not a smart contract flaw in the rsETH token contract itself. That distinction matters. Crypto loves to pretend every disaster is a “smart contract exploit, ” but sometimes the contract is not the weak link at all. The weak link is the machinery outside the chain that tells the chain what to trust.
That machinery included RPC infrastructure, verification services, and the assumptions sitting underneath them. RPC nodes are the endpoints blockchain apps use to read data from a network. If those endpoints are compromised, downstream systems can be tricked into believing a false state. In other words: the chain did not necessarily get broken, but the system feeding it got mugged.
LayerZero said it had previously recommended verifier diversification, and after the exploit it ended support for 1-of-1 DVN configurations. That was not exactly a subtle admission. If one verifier can approve a message, then one compromised verifier can fake a message. Basic security hygiene says you do not build a vault with one lock and then act surprised when somebody picks it.
Kelp did not just sit there and absorb the hit. In May, it migrated rsETH cross-chain transfers from LayerZero’s OFT framework to Chainlink CCIP. By May 25, Kelp said it had transferred the final 20, 373.72 rsETH tranche needed for operational recovery. Minting, redemptions, and rewards had resumed, and bridging reopened after earlier asset transfers restored backing to the affected structure. Kelp also committed 2, 000 ETH to the recovery effort.
That recovery effort mattered beyond Kelp. The stolen rsETH was used as collateral in DeFi, which pulled other protocols into the mess. CoinDesk reported that Aave and other major crypto firms joined a “DeFi United” recovery push, because once collateral gets corrupted, the problem stops being a single-project headache and starts looking like a market stress event. This is the part of DeFi that the glossy pitch decks skip over. One broken trust layer can ripple into lending markets, liquidity, and bad debt before anyone can hit the brakes.
The legal question now is whether LayerZero’s role goes beyond being the infrastructure provider in the background. Kelp says LayerZero approved the setup in writing. LayerZero says Kelp chose the 1-of-1 model. The court will have to sort out what was disclosed, what was approved, who had control over the vulnerable components, and whether the risks were clear enough to shift liability one way or the other.
That is why the British Columbia lawsuit matters. Cross-chain systems are supposed to reduce trust in any one party, but in practice they often rely on a stack of off-chain services, verifiers, and operational assumptions that can fail in ugly ways. When that trust layer breaks, users do not just lose money. They lose the illusion that the plumbing was as decentralized as the marketing copy claimed.
LayerZero co-founder and CEO Bryan Pellegrino has called the lawsuit “meritless” and said he will defend himself and LayerZero in Vancouver. Fair enough, that is what defendants say when they are sued. The real test is whether the filings and incident records show that LayerZero merely provided the rails, or whether it also helped lay the tracks over a pit.
There is also the attribution angle. LayerZero and researchers linked the attack to TraderTraitor and the Lazarus Group, the North Korea-linked threat cluster often tied to major crypto thefts. That may be useful cybersecurity context, but attribution is not a court judgment. In cyber incidents, names can point in the right direction without settling the question of legal responsibility.
The bigger lesson is blunt: verifier diversity is not some optional best practice for brochures and keynote slides. It is what keeps one compromised component from becoming a billion-dollar problem dressed up as a technical nuance. Cross-chain systems can be useful, but they are only as strong as the trust assumptions buried inside them.
KelpDAO sues LayerZero over $292M rsETH exploit
Lazarus-Linked KelpDAO Bridge Hack Drains $290M and Wipes
KelpDAO $292M Hack: Tornado Cash Exploit Shakes DeFi
Kraken Replaces LayerZero with Chainlink CCIP for kBTC
Key questions and takeaways
-
What is Kelp accusing LayerZero of?
Kelp says LayerZero failed to disclose risks, failed to stop attackers from penetrating the verifier infrastructure, and approved the setup in writing. Those claims now sit at the center of the civil case. -
Why does the 1-of-1 DVN matter?
Because it creates a single point of failure. If one verifier can authorize a cross-chain message, compromising that verifier can let attackers move or mint assets without a legitimate burn on the source chain. -
Was the rsETH token contract itself broken?
The reporting points more toward off-chain verification infrastructure than a flaw in the token contract. The issue was the trust layer around the transfer, not necessarily the token code itself. -
Did the damage stay limited to Kelp?
No. Because stolen rsETH was used as collateral, the fallout spilled into DeFi lending markets and recovery efforts involving Aave and other firms. -
What did Kelp do after the exploit?
Kelp moved rsETH cross-chain transfers from LayerZero’s OFT framework to Chainlink CCIP, committed 2, 000 ETH to recovery, and said minting, redemptions, rewards, and bridging resumed after backing was restored. -
Could this case matter beyond LayerZero and Kelp?
Yes. It could help shape how courts think about liability when cross-chain infrastructure fails, especially where one side says the setup was approved and the other says the customer chose the risk.
The uncomfortable truth is that cross-chain infrastructure often looks elegant right up until the moment it fails. Then the conversation turns into a legal food fight over who configured what, who approved what, and who left the door open long enough for the thieves to walk out with the vault.
For builders, the takeaway is brutally simple: verifier diversity is not a nice-to-have. It is the difference between a resilient system and a single compromised assumption with a nine-figure price tag.