CandyPulse

KelpDAO Sues LayerZero Over $292M rsETH Exploit

By CANDY Team · 2026-09-28 · News

A $292 million crypto exploit that began with compromised off-chain infrastructure has moved from post-mortems and social media arguments straight into a courtroom.

Evercrest Technologies, the team behind KelpDAO, has filed a civil suit in the Supreme Court of British Columbia against LayerZero Labs and its CEO, Bryan Pellegrino. The lawsuit stems from an April exploit that drained 116,500 rsETH. KelpDAO alleges that LayerZero reviewed, endorsed, and directed the bridge configuration involved, failed to disclose key security risks, and later misrepresented Kelp’s role in public statements. LayerZero denies the claims, with Pellegrino calling the suit meritless.

While the allegations remain unproven, the case brings an existential question to the forefront of decentralized finance: When modular, third-party infrastructure fails, where does legal and technical liability actually sit?

Beyond the Smart Contract: Anatomy of the Hack

The attack was not a conventional smart-contract flaw. The destination-side smart contracts executed exactly as designed. The failure occurred upstream in the data feeding them.

According to incident reports from Chainalysis and LayerZero, attackers compromised a LayerZero developer through social engineering to gain session credentials. From there, they accessed the RPC infrastructure feeding LayerZero’s Decentralized Verifier Network (DVN). The attackers poisoned RPC nodes, launched denial-of-service attacks against external RPCs, and fed manipulated data directly to the verifier.

The verifier accepted the false data and signed off on a forged cross-chain message confirming a token burn on the source chain that never occurred. The destination bridge accepted the signature and minted unbacked tokens. The on-chain math checked out; the off-chain reality was entirely fabricated.

The Single-Verifier Vulnerability

Cross-chain architectures rely on verifiers to validate state changes between independent networks. KelpDAO’s rsETH bridge was running on a 1-of-1 configuration using LayerZero Labs' sole DVN.

Because only one approval was required, compromising that single pipeline allowed the attacker to drain the bridge. Had a multi-DVN setup been used, an independent verifier would have rejected the mismatch.

The disagreement over why this configuration existed forms the heart of the legal battle:

The narrative shifted in May when LayerZero publicly conceded a misstep, admitting: “We made a mistake by allowing our DVN to act as a 1/1 DVN for high-value transactions.” LayerZero subsequently phased out solo-DVN support for its verifier. While this admission does not automatically imply legal negligence, it undermines clean boundaries between infrastructure provider and integrator.

Contagion in Composable Finance

Kelp managed to pause its contracts and stop an additional drain of 40,000 rsETH (worth ~$95 million at the time), but the initial $292 million loss rippled across DeFi.

Because rsETH serves as collateral across major money markets, the sudden injection of unbacked tokens forced platforms like Aave to evaluate potential bad-debt exposure. Composable architecture allows rapid innovation, but it also creates tight systemic coupling: an attack on a single developer machine can compromise an RPC node, corrupt a verifier, trick a bridge, and threaten collateral pools across unrelated protocols.

KelpDAO has since migrated its cross-chain messaging from LayerZero to Chainlink’s Cross-Chain Interoperability Protocol (CCIP).

The Legal Precedent Facing DeFi

Evercrest's suit covers negligence, negligent misrepresentation, and defamation. As the case proceeds, the court will have to determine:

In traditional finance, service agreements and regulatory frameworks clearly delineate vendor accountability. DeFi has historically operated under "code is law" and decentralized disclaimers.

The KelpDAO v. LayerZero lawsuit signals that the era of settling multi-million-dollar infrastructure failures exclusively through Discord post-mortems and social media statements is ending. As real capital flows into modular web3 networks, the infrastructure layers connecting smart contracts to off-chain reality will increasingly be held accountable in courts of law.


More on CandyPulse

Kraken Parent Payward Expands Beyond Crypto Trading, in No Rush to IPO

XRP Ledger's Batch Upgrade Delayed to October 9 at the Earliest

Solana's Alpenglow Speed Upgrade Reaches Both Public Test Networks

Binance Invests $100 Million in Circle, Signs Five-Year USDC Deal