NewsCryptoKelpDAO Sues LayerZero Over $292 Million rsETH Exploit

KelpDAO Sues LayerZero Over $292 Million rsETH Exploit

Author: Crypto Ninjas·

Key Takeaways

  • •KelpDAO sued LayerZero and CEO Bryan Pellegrino on Sept. 25 over an April exploit that resulted in the theft of 116,500 rsETH valued at roughly $292 million.
  • •LayerZero investigation found the attacker used social engineering to access a developer account and infiltrate the company's RPC system, feeding fraudulent blockchain data that let a malformed cross-chain message receive a valid attestation.
  • •LayerZero argues that KelpDAO's 1-of-1 DVN configuration, with LayerZero Labs as sole verifier, created a single point of failure, while KelpDAO disputes this and claims LayerZero approved the bridge's deployment and configuration in writing.
  • •Chainalysis determined the attackers did not exploit known vulnerabilities in KelpDAO's smart contracts.
  • •After the exploit, KelpDAO moved its rsETH bridge to Chainlink CCIP, and LayerZero removed support for 1-of-1 DVN configurations for compromised applications.
KelpDAO Sues LayerZero Over $292 Million rsETH Exploit

KelpDAO has filed a lawsuit against LayerZero and its co-founder and CEO, Bryan Pellegrino, over an April exploit that resulted in the theft of 116,500 rsETH valued at approximately $292 million.

The legal action moves a dispute that had previously played out through technical reports and public statements into court. KelpDAO alleges that LayerZero failed to disclose important vulnerabilities and risks in its technology and did not adequately secure infrastructure used by its verification system. The allegations have not been substantiated in courtn

KelpDAO Takes LayerZero Dispute to Court

KelpDAO announced the lawsuit on Sept. 25, several months after the April exploit, saying it seeks to hold LayerZero and Pellegrino responsible for losses and damages that the protocol attributes to the exploit.

— Kelp (@KelpDAO) September 25, 2026

The post was published by KelpDAO on X: https://x.com/KelpDAO/status/2103332910128599327?ref_src=twsrc%5Etfw

Pellegrino has dismissed the lawsuit as frivolous and said he intends to contest it in Vancouver. The dispute centers on the parties’ differing accounts of how the bridge became vulnerable and who was responsible for the conditions that allowed the attack.

The $292 Million rsETH Exploit

An attacker stole 116,500 rsETH, which had a total value of approximately $292 million at the time of the incident. According to LayerZero’s investigation, the attacker first used social engineering to gain access through a LayerZero developer before infiltrating the company’s remote procedure call (RPC) system.

The compromised infrastructure supplied fraudulent blockchain data to LayerZero’s verification system. That data allowed a malformed cross-chain message to receive a valid attestation. The false message ultimately triggered the release of rsETH without a corresponding token burn on the source chain. Under this type of bridge mechanism, releases on one chain are meant to be matched by burns on another, keeping the bridged asset’s supply aligned across chains.

Chainalysis determined that the attackers did not exploit known vulnerabilities in KelpDAO’s smart contracts.

Why the 1-of-1 DVN Configuration Is Central

LayerZero says KelpDAO’s rsETH bridge was connected to a 1-of-1 Decentralized Verifier Network (DVN), with LayerZero Labs serving as the sole verifier, meaning a single attestation was sufficient for a cross-chain message to be treated as valid. LayerZero has argued that this configuration created a single point of failure: if the verifier was compromised, no independent verifier was available to reject the forged message.

LayerZero has also said it recommended using multiple DVNs for redundancy. KelpDAO disputes that account, stating that LayerZero reviewed and approved the bridge’s deployment and configuration in writing. That claim is now part of the litigation.

KelpDAO Moves rsETH Away From LayerZero

After the exploit, KelpDAO shifted its focus to the cross-chain security of its system. The protocol moved to transfer the rsETH bridge away from LayerZero’s infrastructure and onto Chainlink CCIP, Chainlink’s cross-chain interoperability protocol.

LayerZero also responded by removing support for 1-of-1 DVN configurations for compromised applications and strengthening infrastructure associated with the attack.

The lawsuit places the technical disagreement under judicial scrutiny. Among the central issues are responsibility for the compromised infrastructure, the bridge’s configuration, and the security warnings provided before the $292 million exploit. The dispute illustrates how cross-chain bridges depend both on the messaging infrastructure beneath them and on the configurations chosen by the applications that use them.

Source: CryptoNinjas