KelpDAO sues LayerZero over $292 million bridge exploit

iEXExchanger
KelpDAO sues LayerZero over $292 million bridge exploit

KelpDAO accuses LayerZero of endorsing a risky bridge security setup and hiding the danger — after the $292 million hack, users pulled $650 million out of the protocol.

KelpDAO has taken LayerZero Labs and its co-founder Bryan Pellegrino to court over one of the biggest DeFi hacks of the year — a $292 million exploit that drained its liquid-restaking token in April. The claim was filed on September 25 in the Supreme Court of British Columbia, in Vancouver.

The breach itself happened back in April, when attackers siphoned off 116,500 rsETH, the synthetic ether KelpDAO mints through cross-chain bridges built on LayerZero's messaging infrastructure. Whoever pulled it off found a way into the verification layer that confirms transactions between blockchains, then pushed through forged messages that looked entirely legitimate on-chain.

Evercrest Technologies, the entity behind KelpDAO, argues the failure goes deeper than a single hack. According to the filing, LayerZero reviewed and signed off on a one-verifier setup back in 2024, calling it a non-issue, then steered KelpDAO toward copying the exact same single-verifier configuration another bridge was already running. Evercrest claims LayerZero never flagged the risk to them, even though it reportedly warned a different client, USDT0, about the same weak point.

LayerZero isn't backing down. "The claim continues to be meritless," Pellegrino said, adding he'll defend himself in Vancouver. LayerZero's own account of events points the finger back at KelpDAO's choice of a single-verifier setup as the actual point of failure, and says the attackers got in through social engineering, tricking their way onto a LayerZero developer's machine.

The fallout spread well past KelpDAO itself. The protocol wound down its sbUSD stablecoin, depositors pulled roughly $650 million out of the system, and JPMorgan analysts estimate the shock wiped around $20 billion off DeFi's total value locked, forcing lenders like Aave to borrow just to cover the redemption rush.

A win for KelpDAO would set a real precedent — it would mean bridge providers can be held liable not just for buggy code, but for the security advice they hand out to the protocols that build on top of them.

Questions and answers

Frequently asked questions about this article

What happened between KelpDAO and LayerZero?

On September 25, 2026, KelpDAO filed a lawsuit against LayerZero Labs and co-founder Bryan Pellegrino in the Supreme Court of British Columbia. The case stems from an April exploit of the rsETH bridge, in which attackers drained 116,500 tokens worth about $292 million.

What exactly is LayerZero accused of?

KelpDAO claims that in 2024 LayerZero reviewed and endorsed a single-verifier setup as risk-free, then advised KelpDAO to copy the same configuration another bridge was already using. The suit alleges LayerZero never disclosed the danger, even though it reportedly warned a different client about the identical weakness.

How did LayerZero respond to the lawsuit?

Co-founder Bryan Pellegrino called the claim meritless and said he'll defend himself in court in Vancouver. LayerZero's own account blames KelpDAO's choice of a single-verifier setup for the vulnerability, and says the attackers got in through social engineering.

What broader impact did the exploit have on DeFi?

KelpDAO shut down its sbUSD stablecoin, users pulled about $650 million from the protocol, and JPMorgan estimates the shock erased roughly $20 billion in DeFi's total value locked, forcing protocols like Aave to borrow funds to cover redemptions.

Why does this lawsuit matter for the wider DeFi industry?

A ruling in KelpDAO's favor would set a precedent: infrastructure providers like LayerZero could become legally liable not just for flaws in their code, but for the security advice they give to protocols that build bridges on their technology.