Key Insights:
- KelpDAOs lawsuit challenges LayerZeros responsibility for the $292 million rsETH exploit.
- Disputed written approvals could become evidence in determining liability.
- The case highlights accountability risks surrounding verifier cross-chain bridge configurations.
KelpDAO has filed a lawsuit against LayerZero and its chief executive, Bryan Pellegrino in British Columbia over the April 18 exploit that drained $292 million from its rsETH bridge. The KelpDAO lawsuit brings months of competing accusations into court raising questions about -chain security, infrastructure accountability and responsibility for losses across decentralized finance.
The action, filed on September 24 by Evercrest Technologies Inc., names LayerZero Labs Ltd. And Pellegrino as defendants. KelpDAO alleges that LayerZero failed to disclose risks and protect infrastructure used to verify cross-chain transactions.
Today we filed a lawsuit against LayerZero and its co-founder, Bryan Pellegrino, to right the wrongs associated with the exploit of rsETHβs LayerZero bridge earlier this year. For more details, please refer to the statement below.https://t.co/gPQTPeM0Zh
— Kelp (@KelpDAO) September 25, 2026
KelpDAO Lawsuit Brings Security Dispute to Court
Evercrest Technologies, the company that created the Kelp application started the process in Vancouver. The court registry, in British Columbia has the case listed under file number 267169.
Pellegrino publicly confirmed the filing before KelpDAO released its statement. On September 24 he described the claims as meritless. Said he would defend himself and LayerZero in Vancouver.
KelpDAO responded early September 25 saying the action seeks accountability for failures connected to the rsETH bridge exploit.
The protocol says that LayerZero read and approved its deployment settings in writing, before the attack. The protocol also says that LayerZero did not share its technology weaknesses and did not stop attackers from breaking into its security system.
However the court has not ruled on these allegations. LayerZero and Pellegrino have disputed KelpDAOs account leaving the contractual questions unresolved.
Competing Accounts of the April Bridge Attack
The dispute began on April 18 2026 when attackers drained 116,500 rsETH from KelpDAOs LayerZero-based bridge. The stolen tokens carried an estimated value of $292 million at the time.
LayerZeros subsequent investigation identified a compromised Decentralized Verifier Network (DVN) as a factor.
According to its May incident report attackers tricked a developer on March 6. Attackers got session credentials. Attackers then went into LayerZeros RPC cloud environment. Attackers changed nodes that support LayerZeros verifier.
During the April attack those compromised nodes supplied blockchain information. Meanwhile attackers disrupted RPC providers through a denial-of-service attack.
Consequently LayerZeros DVN received misleading information. Consequently LayerZeros DVN signed a forged -chain message. Consequently KelpDAOs Ethereum bridge then released rsETH without a burn on the source chain.
The principal technical dispute concerns the verifier configuration.
LayerZero says KelpDAO used a 1-of-1 DVN setup allowing one verifier to authorize messages without confirmation. KelpDAO maintains that LayerZero reviewed its configuration and approved the deployment in writing.
LayerZero argues that multiple independent verifiers would have prevented compromised infrastructure from authorizing the forged message.
KelpDAO also says its deployment followed LayerZeros documented defaults and relied on infrastructure operated by LayerZero. A second attack attempt targeted another 40,000 rsETH. However KelpDAO paused its contracts before that transaction could execute.
DeFi Exposure and Bridge Security Implications
The exploit extended beyond KelpDAO because attackers used stolen rsETH as collateral in decentralized lending markets. Aave and other protocols faced disruptions as the incident spread across applications.
Security investigations identified infrastructure weaknesses than a direct vulnerability in KelpDAOs rsETH token contract. LayerZero subsequently ended support for 1-of-1 DVN configurations. LayerZero pushed affected applications toward independent verification paths.
The KelpDAO lawsuit could establish how courts examine responsibility when an application relies on party-chain infrastructure. The outcome may also clarify how written approvals, technical recommendations and security configurations affect liability.
Nevertheless the filing does not establish negligence or determine damages. Those questions remain subject to court proceedings and evidence presented by both sides.
LayerZero and security researchers also attributed the attack to North Korea-linked TraderTraitor, associated with the Lazarus Group. That attribution concerns the attackers identity, not the responsibility disputed between the companies.
KelpDAO Moves rsETH Away From LayerZero
KelpDAO began changing its infrastructure while recovery efforts continued in May. The protocol announced plans to migrate rsETH transfers from LayerZeros Omnichain Fungible Token framework to Chainlinks Cross-Chain Interoperability Protocol.
The migration followed the security dispute. The migration aimed to introduce a verification framework.
By May 25 KelpDAO reported transferring the 20,373.72 rsETH tranche required for its recovery plan. Minting, redemptions and rewards had resumed, while bridging services reopened after restoration efforts.
KelpDAO also committed 2,000 ETH toward the recovery effort. The process involved DeFi participants because the stolen tokens had affected lending markets.
The KelpDAO lawsuit now places the competing accounts before a British Columbia court. The central questions involve LayerZeros infrastructure, KelpDAOs verifier configuration and the parties documented communications.
Pellegrino has said he intends to contest the claims. The proceedings could clarify responsibility, for the $292 million exploit although no court has established liability or awarded damages.





