KelpDAO sues LayerZero over $292M rsETH exploit
KelpDAO has sued LayerZero and co-founder Bryan Pellegrino in British Columbia over the April 18 exploit that drained 116,500 rsETH worth approximately $292 million.
- KelpDAO filed a British Columbia lawsuit against LayerZero and CEO Bryan Pellegrino over April’s exploit.
- The April attack drained 116,500 rsETH worth approximately $292 million from KelpDAO’s LayerZero bridge infrastructure.
- KelpDAO alleges LayerZero failed to disclose technology risks and secure infrastructure later compromised by attackers.
- LayerZero says KelpDAO’s one-of-one verifier configuration created the single failure point enabling forged cross-chain messages.
- Pellegrino called the lawsuit meritless and said he will defend himself and LayerZero in Vancouver.
KelpDAO said on September 24 that Evercrest Technologies Inc., the legal entity behind Kelp, filed the action to address what it describes as failures connected to LayerZero’s infrastructure. Kelp’s current terms identify Evercrest Technologies Inc. as the company providing the Kelp application.
The complaint, according to KelpDAO’s public account, alleges that LayerZero failed to disclose weaknesses and risks in its technology and failed to stop attackers from penetrating security infrastructure used by its verifier. No court has ruled on those allegations.
Pellegrino disputes the case. He called the claims “meritless” and said he would defend himself and LayerZero in Vancouver. Current reporting confirms the civil claim names both LayerZero and Pellegrino personally.
KelpDAO says LayerZero approved its bridge setup
KelpDAO’s case centers partly on the configuration of the rsETH bridge. The protocol says LayerZero had reviewed and approved its deployment and configuration in writing before the April exploit, contradicting LayerZero’s later argument that Kelp created a dangerous single-verifier setup.
LayerZero has given a different account. In its April incident statement, the company said Kelp used a 1-of-1 Decentralized Verifier Network, or DVN, leaving no separate verifier capable of rejecting a false cross-chain message. LayerZero said it had previously recommended verifier diversification and described the configuration as a single point of failure.
Kelp pushed back days after the attack. As crypto.news reported in its coverage of the dispute over LayerZero’s default configuration, Kelp said its bridge followed LayerZero’s documented defaults and relied on LayerZero-operated infrastructure. LayerZero maintained that Kelp had manually moved to the 1-of-1 configuration.
Pellegrino later said Kelp originally used multi-DVN or DeadDVN defaults before changing the rsETH deployment. Kelp has disputed LayerZero’s description of the discussions and now says its lawsuit will rely on written records showing LayerZero reviewed the setup.
LayerZero’s own infrastructure was compromised
The parties disagree over responsibility, but LayerZero’s final incident report confirms that attackers penetrated infrastructure operated by LayerZero Labs before the rsETH bridge released the funds.
LayerZero published its detailed report in May, saying the intrusion began on March 6 when an attacker socially engineered a LayerZero developer and obtained session credentials. The attacker then entered LayerZero’s RPC cloud environment and altered internal RPC nodes used by the LayerZero Labs DVN.
During the April 18 attack, the compromised nodes supplied false blockchain information while attackers launched a denial-of-service attack against external RPC providers. LayerZero’s DVN then signed a forged message because its available information indicated that the message was valid.
Kelp’s Ethereum bridge subsequently released 116,500 rsETH even though no corresponding burn had occurred on the source chain. Chainalysis described the event as an attack on off-chain verification infrastructure, not a smart contract vulnerability in Kelp’s rsETH token contract.
A second attempt sought another 40,000 rsETH, then worth roughly $95 million to $100 million, but Kelp had paused its contracts before the forged packet could execute. The pause occurred roughly 46 minutes after the successful drain.
As crypto.news reported in its LayerZero incident report coverage, LayerZero responded by ending support for 1-of-1 DVN configurations and moving affected applications toward multi-verifier setups. The company said its updated security model requires more independent verification paths.
Lawsuit follows months of competing blame
KelpDAO’s newly filed action turns a public technical dispute into a civil court case. Kelp says LayerZero and Pellegrino spent months placing responsibility on Kelp after infrastructure controlled by LayerZero was compromised.
LayerZero has maintained that the attacker could not have stolen the rsETH if Kelp had required multiple independent DVNs. Its May report said a hardened configuration requiring separate verifiers to agree would have stopped one compromised verifier from authorizing the forged message.
Security researchers have documented both parts of the failure. Blockaid found that LayerZero’s sole DVN authenticated the false cross-chain message and that the absence of a second verifier allowed it to reach Kelp’s Ethereum adapter.
Chainalysis reached a similar technical finding while focusing on the compromised infrastructure. Its investigation found attackers manipulated LayerZero-operated RPC nodes feeding the DVN and forced the verifier to rely on those nodes by disrupting external providers.
LayerZero and several researchers have attributed the attack to North Korea-linked TraderTraitor, associated with the Lazarus Group. LayerZero’s final report said Mandiant, CrowdStrike and independent researchers reached that attribution.
As crypto.news reported in its coverage of the Lazarus attribution, the finding came from LayerZero’s investigation and associated security work. The lawsuit concerns responsibility between Kelp and LayerZero for the conditions that allowed the exploit; the attribution does not resolve that civil dispute.
Kelp has moved rsETH away from LayerZero
Kelp began changing its bridge infrastructure while recovery work continued. In May, it announced a migration of rsETH cross-chain transfers from LayerZero’s OFT framework to Chainlink CCIP.
Crypto.news reported that Kelp moved rsETH toward Chainlink CCIP as the disagreement with LayerZero continued. Pellegrino disputed Kelp’s account of the original bridge configuration during that migration process.
By May 25, Kelp said it had transferred the final 20,373.72 rsETH tranche needed for its operational recovery plan. Minting, redemptions and rewards had resumed, while bridging services reopened after earlier asset transfers restored backing to the affected structure.
The recovery involved other DeFi platforms because the attacker had used stolen rsETH as collateral. Aave, Kelp and other participants organized a recovery process after the theft created losses in lending markets. As crypto.news previously reported, Kelp committed 2,000 ETH to the rsETH recovery effort as part of that process.
The civil case now moves into British Columbia’s court process. Under the province’s Supreme Court Civil Rules, a defendant generally has 21 days to respond after service in Canada, 35 days after service in the U.S., or 49 days when served elsewhere, unless the court orders another deadline. Pellegrino has publicly said he intends to contest the action in Vancouver.