NewsCryptoKelpDAO Sues LayerZero Over $292 Million rsETH Exploit in Case That Could Test On-Chain Infrastructure Liability

KelpDAO Sues LayerZero Over $292 Million rsETH Exploit in Case That Could Test On-Chain Infrastructure Liability

Author: BitcoinKE·

Key Takeaways

  • •Evercrest Technologies, the company behind KelpDAO, is suing LayerZero Labs, LayerZero Labs Canada, and co-founder Bryan Pellegrino in British Columbia over the April 2026 exploit that drained 116500 rsETH valued at approximately $292 million.
  • •Kelp's claim alleges negligence, negligent misrepresentation, and defamation, asserting that LayerZero failed to disclose security risks and had signed off on the bridge's 1-of-1 decentralized verifier network setup before the attack.
  • •LayerZero maintains the exploit was confined to Kelp's configuration, saying attackers compromised the RPC infrastructure used by its verifier and caused it to approve a forged cross-chain message.
  • •If Kelp succeeds, the case could establish a framework for claims against infrastructure providers such as bridges, oracle operators, validators, and custody services whose technology is integrated into on-chain applications.
  • •No established court precedent currently holds an on-chain infrastructure provider liable for losses from a compromised integration, and the allegations remain untested pending the defendants' formal response and evidence exchange.
KelpDAO Sues LayerZero Over $292 Million rsETH Exploit in Case That Could Test On-Chain Infrastructure Liability

KelpDAO has taken its dispute with cross-chain infrastructure provider LayerZero to court, opening a potentially significant legal test over liability when an on-chain service is compromised.

Evercrest Technologies, the entity behind KelpDAO, filed a civil claim in the Supreme Court of British Columbia against LayerZero Labs, LayerZero Labs Canada, and co-founder Bryan Pellegrino. The claim stems from the April 2026 exploit that drained 116,500 rsETH, Kelp's liquid restaking token, worth approximately $292 million at the time, and seeks to hold the infrastructure provider accountable for losses suffered during the incident.

What Kelp Alleges

Kelp alleges negligence, negligent misrepresentation, and defamation, arguing that LayerZero failed to disclose security risks and that its infrastructure was compromised in a way that allowed attackers to forge a cross-chain message.

A central issue is Kelp's claim that LayerZero had reviewed and endorsed the bridge's 1-of-1 decentralized verifier network (DVN) configuration before the attack. LayerZero disputes that account. In its incident report, the company said the exploit was isolated to Kelp's configuration because the bridge relied on a single DVN, creating a single verification point. According to LayerZero, attackers compromised the RPC infrastructure used by its DVN and caused it to approve a forged message.

DVNs are the components of a cross-chain messaging system responsible for verifying messages in transit; in a 1-of-1 configuration, a single verifier's approval is enough, which is why the disputed review sits at the center of both sides' accounts.

Pellegrino has called the lawsuit meritless and said he will defend LayerZero and himself in British Columbia.

Why the Case Extends Beyond LayerZero

The case is unusual because the dispute is not simply between a victim and a hacker. Kelp is attempting to establish potential liability for an infrastructure provider whose technology was integrated into an on-chain application.

That distinction could matter well beyond LayerZero. If Kelp can establish that LayerZero had a duty to warn about a known security risk, or that its representations about the infrastructure influenced Kelp's deployment decision, the case could provide a framework future claims involving bridges, oracle providers, validators, custody infrastructure, and other services that sit between decentralized applications and the underlying blockchain.

The Existing Legal

There is already legal precedent showing that calling a system “decentralized” does not automatically eliminate potential legal responsibility. In the United States, courts have allowed claims involving developers and participants in DeFi structures to proceed, while a 2026 ruling dismissed a separate class action against Uniswap Labs and its CEO (REGULATION | U.S. Court Dismisses Lawsuit Seeking Regulatory Protections for Non-Custodial Software Solutions).

There is not yet, however, an established court precedent specifically holding an on-chain infrastructure provider liable for losses caused by a compromised integration. The KelpDAO case therefore remains an allegation-driven dispute rather than a settled rule of law.

The case could ultimately turn on evidence outside the smart contracts themselves, including written communications, security recommendations, representations made during the integration process, and the precise responsibilities accepted by each party. For on-chain infrastructure providers, that makes the lawsuit potentially significant: the code may be decentralized, but the contractual and advisory relationships around that code can still end up in court.

As a newly filed claim, the allegations remain untested, and no court has yet ruled on them. The next procedural steps — the defendants' formal response and the exchange of documents and evidence — are where the communications and integration representations at the heart of the dispute would come into focus.

Related Coverage

Source: BitcoinKE