Security & Audits
Share
KelpDAO has filed a civil lawsuit in British Columbia against LayerZero and CEO Bryan Pellegrino, alleging that failures in LayerZero's cross-chain infrastructure enabled a $292 million exploit of KelpDAO's rsETH bridge in April 2026, the largest DeFi exploit of the year. LayerZero's Pellegrino rejected the claim as meritless and said he will defend the case in Vancouver.
KelpDAO has filed a civil claim against LayerZero and its co-founder and CEO Bryan Pellegrino, alleging that failures linked to the cross-chain protocol contributed to a $292 million exploit that became the largest DeFi exploit of 2026 so far.
The legal action centers on the April attack involving KelpDAO’s rsETH bridge, which resulted in the theft of approximately 116,500 rsETH tokens. KelpDAO announced the lawsuit on X on Thursday, accusing LayerZero of failing to disclose weaknesses in its technology and adequately protect the infrastructure used to verify cross-chain transactions.
KelpDAO, a decentralized liquid restaking protocol operating on Ethereum, said the exploit was directly connected to weaknesses and risks it alleges were present in LayerZero’s technology.
According to KelpDAO, LayerZero failed to adequately disclose vulnerabilities associated with its infrastructure and did not prevent attackers from compromising security systems involved in the bridge.
The protocol also accused LayerZero and Pellegrino of publicly assigning responsibility to KelpDAO after the incident rather than accepting responsibility for what KelpDAO described as failures in the underlying infrastructure.
KelpDAO’s claims have not been established by a court. The lawsuit now puts the technical and contractual dispute between the two companies into a formal legal process.
The case is particularly significant because cross-chain bridges are critical infrastructure for moving assets between blockchain networks, meaning security failures can potentially affect more than the protocol directly targeted.
Pellegrino responded to the lawsuit by confirming that a civil claim had been filed against him and LayerZero in British Columbia, Canada.
He identified Evercrest as the entity behind KelpDAO and described the claim as “meritless.” Pellegrino said he would defend himself and LayerZero in Vancouver.
His response reflects LayerZero’s opposing position in the dispute, with the company and its co-founder rejecting the basis of KelpDAO’s allegations.
The legal proceedings will therefore have to address competing accounts of how the exploit occurred and where responsibility for the resulting losses should ultimately lie.
The dispute stems from an attack in April that drained roughly 116,500 rsETH from KelpDAO’s LayerZero-powered bridge.
The stolen tokens represented approximately 18% of rsETH’s circulating supply and were worth about $292 million at the time of the attack. Reports identified the incident as the largest crypto exploit of 2026 at the time, as well as the largest DeFi exploit of the year.
The attack had consequences beyond KelpDAO itself. The stolen, unbacked rsETH was deposited into DeFi lending markets, particularly Aave, where it was used as collateral to borrow other assets.
This created additional pressure on protocols that had accepted rsETH as collateral and demonstrated how an exploit affecting one part of DeFi infrastructure can quickly spread through interconnected markets.
Aave experienced a sharp increase in borrowing and withdrawals following the incident.
Within hours, users and large holders withdrew billions of dollars from Aave liquidity pools, contributing to extremely high utilization across major pools. Some users subsequently borrowed roughly $300 million against their own deposits as liquidity conditions deteriorated.
The event highlighted a key feature of DeFi markets: protocols can remain operational while still being exposed to failures elsewhere in the ecosystem.
Aave itself was not the direct target of the attack, but the platform accepted rsETH as collateral. Once the stolen tokens entered the market without corresponding backing, the value of the collateral and the loans built against it came under pressure.
The consequences were also reflected in broader DeFi market metrics.
Aave’s total value locked fell sharply following the incident, while lending activity and liquidity conditions came under pressure. The episode also renewed concerns over the interconnected risks created when liquid restaking tokens are used across lending protocols and other applications.
The incident demonstrated that the impact of a bridge exploit is not necessarily limited to the assets held by the affected protocol. Once compromised assets enter lending platforms, decentralized exchanges or other applications, the resulting losses can spread through multiple layers of financial infrastructure.
That interconnectedness is one reason bridge and cross-chain security has become a major concern for the DeFi sector.
Following the exploit, KelpDAO said it took steps to strengthen protections for user assets.
Among those measures was moving the rsETH bridge to a more secure cross-chain security standard. The protocol said the changes were intended to improve the protection of user funds and reduce exposure to similar vulnerabilities in the future.
However, KelpDAO argued that technical remediation alone was insufficient.
The protocol said it also wanted to correct what it viewed as an inaccurate account of the incident and hold LayerZero and Pellegrino accountable for the damage caused to KelpDAO and the wider DeFi ecosystem.
The dispute between KelpDAO and LayerZero could have broader implications for projects that rely on third-party infrastructure to move assets between networks.
At the center of the case is not only the $292 million loss, but also the question of how responsibility should be divided when a protocol uses external cross-chain technology and suffers an exploit involving that infrastructure.
The lawsuit could therefore become a closely watched case for the DeFi sector. As bridges, messaging protocols and decentralized applications become increasingly interconnected, determining where security responsibility begins and ends is becoming more complicated.
For KelpDAO, the April exploit demonstrated the financial consequences of that interdependence. For LayerZero, the legal dispute presents an opportunity to contest the allegations and establish its position on the events surrounding the breach.
The outcome could ultimately influence how DeFi projects assess third-party infrastructure, configure bridge security and allocate responsibility for failures. Beyond the immediate legal battle, the case underscores a broader issue facing decentralized finance: technical decentralization does not necessarily eliminate dependence on shared infrastructure, and when that infrastructure fails, tracing accountability can be as difficult as containing the financial damage.
Disclaimer of Warranty
The information provided in this article is for general informational purposes only. We make no warranties about the completeness, reliability, and accuracy of this information. Read full disclaimer
Editor's Picks
In the Same Space

EBA Urges EU to Regulate Crypto Lending and DeFi Under MiCA
News Desk
Sep 25, 2026
4 min

MFTA Report: ADGM Expands Digital Asset and Staking Regulatory Framework
Chantal Assi
Sep 22, 2026
7 min

CFTC Updates Tokenized Asset and Blockchain Rules as Crypto Bill Stalls
News Desk
Sep 25, 2026
5 min

ARK Invest’s $1.3B Fund Heads to Ethereum Through Tokenization
News Desk
Sep 25, 2026
3 min