Submit a Request

KelpDAO Sues LayerZero and Co-Founder Bryan Pellegrino

Published On
26 Sep 2026 05:48
AuthorVigneshwaran Palanisamy

KelpDAO has sued cross-chain interoperability protocol LayerZero and its co-founder and CEO, Bryan Pellegrino, over an April exploit that drained approximately $292 million worth of rsETH from its LayerZero-powered bridge.

Evercrest Technologies Inc., the company behind KelpDAO, filed the civil claim in British Columbia on September 24, 2026. The lawsuit marks a major escalation in the dispute between the two crypto infrastructure providers, which have spent months arguing over whether the loss resulted from LayerZero’s compromised systems, KelpDAO’s bridge configuration, or both.

KelpDAO Blames LayerZero Security Failures

According to KelpDAO, the exploit was caused by LayerZero’s failure to disclose weaknesses in its technology and protect the security infrastructure used to verify cross-chain messages. In a statement published on X, KelpDAO alleged that LayerZero had reviewed and endorsed its deployment and configuration in writing before the incident. The protocol also claimed that attackers infiltrated LayerZero’s internal systems and used the compromise to manipulate the verification process.

“Our number one priority has always been and will remain the security of our users’ assets,” KelpDAO said. The protocol added that it filed the lawsuit to correct the public record and hold LayerZero and Pellegrino accountable for the damage caused to users and the wider decentralized finance ecosystem.

LayerZero and Pellegrino have rejected the allegations. Pellegrino described the civil claim as “meritless” and said he would defend himself and LayerZero in Vancouver. The court has not yet ruled on the allegations, and the precise damages sought by KelpDAO have not been independently confirmed.

How the rsETH Bridge Exploit Happened

The attack took place on April 18, when a LayerZero-powered bridge released 116,500 rsETH on Ethereum without a matching token burn on the originating network. The stolen tokens were valued at roughly $292 million at the time. The bridge relied on a 1-of-1 Decentralized Verifier Network, or DVN, configuration. In practical terms, this meant that a single verification route was required to approve an incoming cross-chain message.

LayerZero’s account of the incident stated that attackers compromised internal infrastructure and caused the verifier to approve a forged message. Once the message was accepted, the bridge released the rsETH as if the tokens had legitimately been burned elsewhere. LayerZero has argued that the single-verifier setup created a critical point of failure. It said that multiple independent verifiers had been recommended for high-value transactions. KelpDAO, however, maintains that LayerZero had approved its configuration and failed to clearly communicate the associated risks.

Dispute Over Responsibility

The lawsuit centers on whether LayerZero had a duty to warn KelpDAO about the risks of its verification model and whether its security infrastructure was adequately protected. LayerZero has acknowledged that its infrastructure was compromised but has continued to highlight KelpDAO’s 1-of-1 DVN configuration. KelpDAO disputes that explanation, arguing that the configuration was accepted by LayerZero before the exploit.

Following the incident, LayerZero moved away from supporting 1-of-1 DVN configurations for high-value transfers and shifted toward multi-verifier security models. KelpDAO also announced plans to migrate its rsETH bridge to Chainlink’s Cross-Chain Interoperability Protocol and other infrastructure.

Impact on DeFi

The exploit affected more than KelpDAO. Attackers reportedly deposited a large portion of the newly created rsETH into Aave and used it as collateral to borrow assets, creating significant risks for the lending protocol. The incident renewed concerns about cross-chain bridges, which depend on external messaging and verification systems to confirm events across different blockchains. Even when the underlying smart contracts function as designed, a compromised verifier can transmit false information and trigger the release of valuable assets.

The British Columbia case could therefore have broader implications for DeFi developers, bridge providers and users. A court decision may help clarify how responsibility is divided when a protocol relies on third-party infrastructure for security-critical operations. For now, the allegations remain contested. KelpDAO says LayerZero’s failures caused the exploit, while LayerZero and Pellegrino plan to challenge the claim. The legal battle will determine whether the losses were primarily the result of infrastructure security failures, an unsafe bridge configuration, or a combination of both.


Leave a Comment