Newsroom
25 September, 2026 / News / AI / Tags: layerzero, kelpdao, rseth, verifier, pellegrino

Liquid staking protocol alleges failures in cross-chain infrastructure and undisclosed risks led to April theft of 116,500 rsETH; LayerZero co-founder calls claims meritless
KelpDAO has initiated legal action against LayerZero and its co-founder Bryan Pellegrino in the Supreme Court of British Columbia, seeking accountability for a major exploit earlier this year that drained approximately $292 million in rsETH tokens from its cross-chain bridge.
The lawsuit, filed by Evercrest Technologies Inc., the legal entity behind KelpDAO, centers on the April incident in which attackers extracted 116,500 rsETH. KelpDAO contends that weaknesses in LayerZero’s technology and security practices enabled the breach, and that the cross-chain protocol had previously reviewed and endorsed the specific bridge configuration in writing.
On or around April 18 to April 22, attackers compromised infrastructure operated by LayerZero Labs. According to LayerZero’s subsequent incident report, the intrusion began in early March when an attacker used social engineering to obtain session credentials from a developer. The attackers then accessed LayerZero’s RPC cloud environment and altered internal nodes used by its decentralized verifier network.
During the attack, the compromised nodes provided false blockchain data. Combined with a denial-of-service campaign against external RPC providers, this led LayerZero’s verifier to approve a forged cross-chain message. KelpDAO’s Ethereum bridge then released the 116,500 rsETH without a corresponding burn on the source chain. A follow-up attempt targeting an additional roughly 40,000 rsETH, valued at about $95 million to $100 million at the time, was blocked after KelpDAO paused its contracts approximately 46 minutes after the initial drain.
Security firms including Chainalysis characterized the event as an attack on off-chain verification infrastructure rather than a vulnerability in KelpDAO’s smart contracts. LayerZero and multiple researchers attributed the operation to the North Korea-linked TraderTraitor group associated with Lazarus.
KelpDAO’s complaint alleges that LayerZero failed to disclose inherent risks in its technology and did not prevent attackers from penetrating its security systems. The protocol further asserts that LayerZero had approved its deployment and configuration in advance, contradicting later statements that the bridge relied on an insecure single-verifier setup.
LayerZero has maintained a different position. In its May incident report, the company stated that KelpDAO configured its bridge with a 1-of-1 decentralized verifier network, creating a single point of failure. LayerZero said it had previously recommended verifier diversification and that a multi-verifier requirement would have prevented the forged message from succeeding. Pellegrino has stated that KelpDAO originally used multi-verifier defaults before changing the configuration.
KelpDAO has disputed this characterization, arguing that its setup followed LayerZero’s documented defaults and relied on LayerZero-operated infrastructure. The lawsuit now seeks to resolve these competing technical and contractual claims in court.
The exploit contributed to significant market disruption. It triggered liquidity pressures across decentralized finance platforms, including elevated borrowing activity on Aave, and coincided with a broader decline of approximately $20 billion in total value locked across DeFi protocols.
In the months following the incident, KelpDAO migrated its rsETH cross-chain transfers away from LayerZero’s OFT framework to Chainlink’s Cross-Chain Interoperability Protocol. By late May, the protocol reported completing the transfer of remaining rsETH needed for operational recovery, resuming minting, redemptions, and rewards, and reopening bridging services after restoring backing assets. KelpDAO also contributed 2,000 ETH to a joint recovery fund involving other DeFi participants affected by the use of stolen rsETH as collateral.
LayerZero responded by ending support for 1-of-1 verifier configurations and requiring applications to adopt multi-verifier setups. The company has described its updated model as requiring more independent verification paths.
The civil claim names both LayerZero and Pellegrino personally. Under British Columbia court rules, defendants generally have between 21 and 49 days to respond depending on the location of service, unless the court sets a different timeline. Pellegrino has publicly confirmed his intention to contest the action in Vancouver.
No court has yet ruled on the allegations. The case elevates a months-long public technical dispute into formal litigation over responsibility for one of the largest exploits recorded in 2026 to date.









