KelpDAO sues LayerZero and its CEO over the $292 million rsETH bridge exploit
The restaking protocol filed a civil claim in British Columbia, blaming LayerZero for April's hack. The fight turns on one setting: whether a single verifier was enough to secure a bridge holding about a fifth of rsETH.
KelpDAO, the Ethereum liquid restaking protocol behind the rsETH token, has sued cross-chain messaging protocol LayerZero and its co-founder and chief executive Bryan Pellegrino over the exploit that drained its rsETH bridge in April. The attacker took 116,500 rsETH, worth about $292 million at the time, according to CoinDesk and Cointelegraph. CoinDesk called it the largest exploit of 2026. The two outlets give different dates for the attack, April 22 and April 18.
Pellegrino said on X that Evercrest, the entity behind KelpDAO, had filed a notice of civil claim in British Columbia against him and LayerZero. "The claim continues to be meritless. I will meet them in Vancouver and defend myself accordingly," he wrote, as quoted by CoinDesk. The reports did not give a damages figure.
The dispute in one setting
KelpDAO says the loss was "a direct result of LayerZero's failures, including a failure to disclose weaknesses and risks inherent in LayerZero's own technology." It also says LayerZero reviewed and endorsed its bridge configuration in writing before the attack, according to Cointelegraph.
LayerZero's final incident report, as summarised by Cointelegraph, tells it differently. Attackers compromised LayerZero's internal nodes and got its verifier to approve a forged cross-chain message. But the bridge released the tokens because Kelp relied on a single LayerZero verifier network as its only check. With no second, independent verifier required, one compromised approval was enough. LayerZero says it had recommended using several verifiers, and has since stopped acting as the sole required verifier for any application. Kelp has said it will move the rsETH bridge to Chainlink's cross-chain protocol.
So both sides agree LayerZero's infrastructure was breached. The case is about who is responsible for a setup in which that breach alone could release $292 million.
Why it went beyond Kelp
The bridge held nearly a fifth of rsETH's circulating supply, CoinDesk reported. The hack helped set off a run in which about $20 billion left decentralized finance deposits, and Aave, the largest DeFi lending platform, borrowed $300 million to meet withdrawals, according to CoinDesk.
The stolen rsETH was worth about $2,506 a token at the time, by our arithmetic from the reported figures. Ether traded at about $2,715 on Coinbase on Friday morning.
What it means for anyone holding bridged tokens
The practical point for traders and treasuries is that a bridged or wrapped token is only as safe as the weakest check on the bridge behind it. A lawsuit will not change how existing bridges are configured. Holders of any token that moves between chains can ask the issuer a plain question: how many independent parties have to sign off before tokens are released? In Kelp's case the answer was one.
| Coin | Price | 24h |
|---|---|---|
| Bitcoin BTC | … | … |
| Ethereum ETH | … | … |
| Solana SOL | … | … |
| XRP XRP | … | … |
| Dogecoin DOGE | … | … |
| Cardano ADA | … | … |
| Chainlink LINK | … | … |
| Avalanche AVAX | … | … |
Live from Coinbase · updated
Sources: CoinDesk; Cointelegraph; Coinbase. The per-token figure is a Chronicle calculation. This is market information, not investment advice.
Want your business to be the answer?
Get a full package of articles about your business, built so customers, Google and AI assistants can find you.