KelpDAO has filed a lawsuit in British Columbia against LayerZero and its co-founder Bryan Pellegrino over the April 18 exploit that drained 116,500 rsETH, valued at about $292 million, from the protocol’s bridge infrastructure.
The case follows months of public disagreement over who was responsible for the failure. KelpDAO says LayerZero did not properly disclose technology risks and failed to secure infrastructure that attackers later compromised. LayerZero rejects that account and argues the loss was only possible because KelpDAO used a one-of-one verifier setup that created a single point of failure.
Dispute centers on bridge design
At the heart of the lawsuit is the configuration used for KelpDAO’s rsETH bridge. KelpDAO says LayerZero reviewed and approved the deployment and configuration in writing before the exploit, which it says conflicts with LayerZero’s later claim that Kelp had chosen an unsafe setup.
LayerZero has maintained that KelpDAO used a 1-of-1 decentralized verifier network configuration, meaning there was no independent verifier available to reject a false cross-chain message. KelpDAO, by contrast, says its bridge followed LayerZero’s documented defaults and depended on infrastructure operated by LayerZero. Pellegrino later said Kelp had originally used multi-DVN defaults before changing the rsETH deployment, a description Kelp disputes and says will be challenged with written records in court.
What LayerZero’s incident report said
Although the parties disagree over liability, LayerZero’s final incident report confirmed that attackers breached infrastructure run by LayerZero Labs before the rsETH bridge released funds. According to that report, the intrusion began on March 6 when a LayerZero developer was socially engineered and the attacker obtained session credentials.
LayerZero said the attacker then entered its RPC cloud environment and modified internal RPC nodes used by the LayerZero Labs DVN. During the April 18 exploit, those compromised nodes allegedly fed false blockchain data while the attackers also launched a denial-of-service attack against external RPC providers. LayerZero’s DVN then signed a forged message as though it were valid, and Kelp’s Ethereum bridge released 116,500 rsETH even though no matching burn had taken place on the source chain.
Chainalysis described the incident as an attack on off-chain verification infrastructure rather than a smart contract flaw in Kelp’s rsETH token. Security researchers cited in the aftermath reached similar conclusions, pointing to both the compromised LayerZero-operated RPC nodes and the lack of a second verifier that could have blocked the forged message.
Public blame battle now moves to court
KelpDAO says LayerZero and Pellegrino spent months assigning blame to Kelp after infrastructure under LayerZero’s control had been compromised. LayerZero has continued to argue that the theft would not have succeeded if Kelp had required multiple independent DVNs. Its May report said a hardened setup with separate verifiers would have prevented a compromised verifier from authorizing the forged message.
Pellegrino has called the lawsuit meritless and said he plans to defend both himself and LayerZero in Vancouver. LayerZero and several researchers have also attributed the attack to TraderTraitor, a North Korea-linked group associated with Lazarus, though that attribution does not settle the civil claims between the companies.
The exploit nearly went further. A second attempt sought another 40,000 rsETH, but KelpDAO said it paused its contracts about 46 minutes after the initial drain.
Recovery steps and what comes next
As recovery efforts continued, KelpDAO began moving its bridge setup away from LayerZero’s OFT framework to Chainlink CCIP. By May 25, the protocol said it had transferred the final 20,373.72 rsETH tranche needed for its operational recovery plan. It also said minting, redemptions and rewards had resumed, and bridging services had reopened after asset transfers restored backing.
LayerZero, for its part, said it ended support for 1-of-1 DVN configurations and shifted affected applications toward multi-verifier designs that require more independent verification paths.
The lawsuit now enters British Columbia’s court process. Under the province’s Supreme Court Civil Rules, a defendant generally has 21 days to respond after service in Canada, 35 days if served in the United States, or 49 days if served elsewhere, unless the court sets a different deadline. Pellegrino has already said he intends to contest the case in Vancouver.
Source: crypto.news