KelpDAO is suing LayerZero in a British Columbia court over the $292 million rsETH exploit, arguing the cross-chain infrastructure provider failed to disclose risks and secure the systems behind its bridge, a claim LayerZero co-founder Bryan Pellegrino has already dismissed as “meritless.”
KelpDAO turns rsETH exploit dispute into legal action
KelpDAO’s legal entity, Evercrest Technologies, has filed the civil claim against LayerZero and Pellegrino in British Columbia.
According to reports on the filing, KelpDAO alleges that LayerZero failed to adequately disclose weaknesses and risks associated with its technology and failed to prevent attackers from compromising infrastructure used by its verifier.
KelpDAO also argues that LayerZero had reviewed and approved its deployment and configuration in writing. Those assertions are allegations contained in the legal dispute and have not been established by a court.
The lawsuit follows months of disagreement over the cause of the rsETH exploit. KelpDAO has maintained that the infrastructure involved in the attack was connected to LayerZero, while LayerZero has emphasized the security configuration selected for KelpDAO’s application.
LayerZero links rsETH exploit to single-verifier setup
LayerZero’s technical investigation provides a different account of how the rsETH exploit occurred. The company said the attack began weeks before the theft, when an attacker socially engineered a LayerZero developer and obtained session credentials.
According to LayerZero’s May incident report, the attacker subsequently gained access to its RPC cloud environment and compromised internal RPC infrastructure used by the LayerZero Labs Decentralized Verifier Network, or DVN.
During the April 18 attack, the compromised infrastructure supplied manipulated information to the verification system. LayerZero said the attacker also disrupted an external RPC provider, increasing reliance on the compromised internal infrastructure.
The result was a forged cross-chain message that the verification system accepted. KelpDAO’s bridge then released approximately 116,500 rsETH even though there was no corresponding token burn on the source chain.
Chainalysis separately characterized the incident as an attack on off-chain infrastructure rather than a conventional smart-contract exploit.
LayerZero has argued that the damage was enabled by KelpDAO’s 1-of-1 DVN configuration, in which LayerZero Labs was the sole verifier. Under such a structure, there was no second independent verifier available to reject a fraudulent message.
LayerZero also said its recommended approach was to use multiple independent DVNs with redundancy, reducing the possibility that one compromised verification path could authorize a fraudulent transaction.
The company later announced changes to its security approach following the rsETH exploit, including ending support for applications using 1-of-1 DVN configurations and encouraging affected applications to adopt multiple verification paths.
Bryan Pellegrino rejects KelpDAO’s allegations
Pellegrino has rejected KelpDAO’s claims, describing the case as “meritless” and saying that he intends to defend himself and LayerZero in Vancouver. His characterization represents the defendants’ position and is not a judicial determination about the merits of KelpDAO’s allegations.
The dispute is consequently centered on two related but distinct questions. The first concerns the compromise of LayerZero-related infrastructure. LayerZero’s own incident report acknowledges that attackers infiltrated infrastructure connected to its DVN before the rsETH exploit occurred.
The second concerns whether KelpDAO’s decision to operate the bridge with a single verifier materially increased the likelihood that the infrastructure compromise could result in a catastrophic asset release.
If KelpDAO can substantiate its claim that LayerZero reviewed and approved the relevant configuration, the documentation could become an important part of its case.
Conversely, LayerZero can point to its position that multi-DVN redundancy was the appropriate security model and that KelpDAO’s 1-of-1 configuration created a single point of failure.
The court will ultimately determine how those competing claims should be treated under applicable law.
What the rsETH exploit means for cross-chain investors
The financial consequences of the rsETH exploit extended beyond KelpDAO itself. The attacker obtained 116,500 rsETH, worth approximately $292 million at the time of the incident.
Because rsETH was used throughout decentralized finance, the stolen assets also created consequences for lending and collateral markets. The technical sequence is particularly important for investors assessing cross-chain assets.
A smart contract can operate exactly according to its programmed rules while still producing an unwanted result if the external information supplied to it is fraudulent.
In this case, the critical issue was not simply whether the bridge contract could release tokens. It was whether the verification system could reliably establish that a legitimate cross-chain event had occurred.
LayerZero has said the incident was contained to KelpDAO’s rsETH configuration and that it did not result in contagion across other LayerZero applications. The company also emphasized that its architecture allows applications to choose their own security configuration.
The rsETH exploit also illustrates why cross-chain infrastructure deserves the same level of scrutiny as smart contracts, custody arrangements and token economics.
The legal dispute is now the next chapter
KelpDAO’s lawsuit does not resolve the technical disagreement surrounding the rsETH exploit. Instead, it creates a formal process through which the competing accounts can be tested.
KelpDAO alleges that LayerZero failed in areas including risk disclosure and infrastructure security. LayerZero has maintained that KelpDAO’s single-DVN configuration was a critical factor in allowing the compromised verification environment to produce a valid-looking message.
The case could influence how decentralized applications document vendor approvals, how cross-chain providers structure default security settings and how protocols divide responsibility when third-party infrastructure is compromised.
The rsETH exploit has already prompted changes to LayerZero’s approach to single-verifier configurations. KelpDAO has also taken steps to move its cross-chain infrastructure toward another standard following the attack.
As the legal proceedings develop, investors should distinguish between established facts, technical findings and allegations made by either side. The April theft is established: approximately 116,500 rsETH was released through the affected bridge. The precise allocation of legal responsibility remains disputed.
The rsETH exploit therefore remains more than a $292 million loss. It has become a test of how the crypto industry assigns accountability when an application, an infrastructure provider and a compromised verification layer intersect.
The court proceedings in British Columbia will now determine how much responsibility, if any, belongs to the parties named in the claim.