
A dispute that has simmered for months in public statements and technical reports has now escalated into a formal courtroom fight. KelpDAO has filed a lawsuit against LayerZero and its co-founder Bryan Pellegrino in British Columbia, seeking accountability for the April exploit that drained roughly $292 million in rsETH from Kelp’s cross-chain bridge. The KelpDAO lawsuit against LayerZero marks the moment a bitter blame game over one of DeFi’s biggest bridge failures moved from social media threads into a courthouse.
Key takeaways
- KelpDAO, through its legal entity Evercrest Technologies Inc., sued LayerZero and co-founder Bryan Pellegrino in British Columbia over the April 18 exploit.
- The attack drained 116,500 rsETH, worth approximately $292 million, from Kelp’s LayerZero-based bridge infrastructure.
- KelpDAO alleges LayerZero failed to disclose technology risks and did not prevent attackers from infiltrating security infrastructure tied to its verifier.
- Pellegrino called the claims “meritless” and said he will defend himself and LayerZero in Vancouver.
- LayerZero’s own incident report confirmed attackers compromised infrastructure it operated before the forged transaction went through.
KelpDAO Sues LayerZero Over $292 Million rsETH Exploit
KelpDAO‘s case centers on an April 18 attack that emptied 116,500 rsETH, worth about $292 million at the time, from the protocol’s bridge built on LayerZero’s cross-chain messaging network. Kelp confirmed the filing through a post from its official account, stating that Evercrest Technologies Inc., the entity behind the Kelp application, brought the action “to right the wrongs associated with the exploit of rsETH’s LayerZero bridge earlier this year.”
Details of the Lawsuit
The civil claim names both LayerZero as a company and Pellegrino personally, filed in a British Columbia court. According to Kelp’s public account of the complaint, no court has yet ruled on the allegations, and the case now moves through the province’s standard civil procedure, which gives defendants a set window to respond depending on where they were served.
Claims of Technology Risk and Security Failure
KelpDAO’s complaint alleges that LayerZero failed to disclose weaknesses and risks embedded in its technology and did not stop attackers from penetrating the security infrastructure tied to its verifier network. Kelp also says LayerZero had reviewed and approved the rsETH bridge’s deployment and configuration in writing before the exploit happened, a claim that directly contradicts LayerZero’s later position that Kelp’s own setup created the vulnerability.
This is where the two sides diverge sharply. LayerZero’s April incident statement described Kelp’s bridge as running a 1-of-1 Decentralized Verifier Network, or DVN, meaning there was no second, independent verifier available to catch or reject a fraudulent cross-chain message. The company said it had previously recommended diversifying verifiers and framed the single-DVN setup as a structural weak point. Kelp has pushed back on that narrative, arguing its bridge followed LayerZero’s own documented default settings and relied on infrastructure that LayerZero itself operated.
LayerZero and Bryan Pellegrino Respond to Allegations
LayerZero and Pellegrino reject the lawsuit outright, framing it as an attempt to shift blame for a configuration choice Kelp made on its own bridge. The company’s own technical account, however, also acknowledges that its infrastructure was breached before the funds moved.
Pellegrino’s Rejection of Claims
Pellegrino publicly dismissed the lawsuit, calling the claims “meritless” and saying he will defend himself and LayerZero in Vancouver. His response came shortly after Kelp announced the filing, and he has separately disputed Kelp’s account of how the bridge was originally configured, saying Kelp had used multi-DVN or DeadDVN defaults before switching the rsETH deployment to the single-verifier setup that LayerZero later flagged as a single point of failure.
Legal Defense Intentions
Pellegrino’s statement signals he intends to contest the case directly rather than settle, setting up a legal fight over responsibility for an attack whose technical mechanics are, in some ways, already well documented. LayerZero’s own May incident report traced the intrusion to March 6, when an attacker allegedly used social engineering against a LayerZero developer to obtain session credentials, then entered the company’s RPC cloud environment and altered internal nodes used by its DVN. During the April 18 attack, those compromised nodes reportedly fed false blockchain data while a denial-of-service attack hit external RPC providers, and the DVN ultimately signed a forged message because the information available to it indicated the transaction was valid.
Why this matters beyond the two companies involved: the case puts a spotlight on how responsibility gets divided when a cross-chain bridge relies on infrastructure operated by a third-party messaging protocol. If a court finds LayerZero’s security lapses were the deciding factor, it could reshape how DeFi protocols negotiate liability clauses with bridge providers going forward. If instead the ruling favors LayerZero’s argument that Kelp’s own configuration choice created the opening, it would reinforce pressure on protocols to adopt multi-verifier setups regardless of what a provider recommends as default.
Security researchers who examined the incident found elements supporting both sides of the argument. Some analyses concluded that the lack of a second, independent verifier allowed the forged message to reach Kelp’s Ethereum adapter unchecked, while other investigations focused on how attackers manipulated LayerZero-operated RPC nodes feeding that same verifier. LayerZero has since ended support for 1-of-1 DVN configurations altogether, pushing applications toward multi-verifier setups as part of a broader security overhaul following the incident.
What Happens Next
Kelp has already moved to change its infrastructure while the legal dispute plays out, migrating rsETH’s cross-chain transfers away from LayerZero’s messaging framework toward a different provider, and it has taken steps to restore backing and resume normal bridging operations for the token. None of that operational recovery resolves the underlying legal question the KelpDAO lawsuit against LayerZero now puts before a British Columbia court: who bears responsibility when a bridge’s security architecture and the infrastructure behind it both come from the same partner.
FAQ
Who filed the lawsuit related to the rsETH exploit?
KelpDAO filed the lawsuit against LayerZero and its co-founder Bryan Pellegrino.
What is the financial amount involved in the rsETH exploit lawsuit?
The lawsuit concerns the $292 million rsETH exploit.
What allegations has KelpDAO made against LayerZero?
KelpDAO alleges LayerZero failed to disclose technology risks and did not prevent infiltration of its security infrastructure.
How has Bryan Pellegrino responded to the lawsuit?
Bryan Pellegrino called the claims meritless and stated he will defend himself accordingly.
Article produced with the assistance of artificial intelligence and reviewed by the editorial team.

4 hours ago
29









English (US) ·