What to Know

  • KelpDAO has sued LayerZero and its co-founder Bryan Pellegrino over a $292 million exploit tied to rsETH.
  • The decentralized liquid staking protocol alleges undisclosed weaknesses in LayerZero’s cross-chain technology enabled the attack.
  • The April 22 incident drained 116,500 rsETH from KelpDAO’s cross-chain bridge.
  • KelpDAO said the exploit was the largest DeFi exploit of this year so far.
  • Pellegrino rejected the lawsuit as meritless and said he will defend himself and LayerZero in British Columbia, Canada.
  • KelpDAO alleged that LayerZero failed to prevent infiltration of its security infrastructure.
  • The attack allegedly involved a North Korean hacking group.
  • The incident contributed to pressure across DeFi markets, including a liquidity crunch that affected stablecoin and lending activity.
  • Aave, the largest decentralized finance lending pool, was forced to borrow $300 million to meet rising withdrawal demand.
  • Days after the exploit, $20 billion in total value locked was erased across decentralized finance deposits.

KelpDAO Files Civil Claim Against LayerZero

KelpDAO has opened a major legal front in the decentralized finance sector, filing a lawsuit against LayerZero and co-founder Bryan Pellegrino over a $292 million exploit that hit the rsETH ecosystem. The case centers on allegations that LayerZero’s cross-chain infrastructure contained weaknesses and risks that were not disclosed, and that those alleged weaknesses enabled attackers to drain a large amount of rsETH from KelpDAO’s bridge.

The dispute places cross-chain security, protocol accountability, and risk disclosure at the center of one of the most closely watched DeFi controversies of the year. KelpDAO, a decentralized liquid staking protocol on Ethereum, said the exploit was a direct result of LayerZero’s failures, including what it described as a failure to disclose weaknesses and risks inherent in LayerZero’s own technology.

LayerZero is known in crypto markets as a universal bridge protocol designed to move assets and messages across different blockchain networks. Such infrastructure plays a critical role in DeFi because it allows liquidity, tokens, and applications to interact beyond a single chain. But bridge systems have long been viewed by security specialists and market participants as among the most complex and vulnerable points in crypto infrastructure, since they often depend on communication layers, validation mechanisms, and security assumptions that differ from the underlying blockchains they connect.

April 22 Attack Drained 116,500 rsETH

The lawsuit follows an April 22 attack on KelpDAO’s cross-chain bridge. The incident drained 116,500 rsETH, with the stolen tokens valued at roughly $292 million. At the time of the attack, the bridge was holding nearly a fifth of the restaked token’s circulating supply, making the exploit not only large in dollar terms but also systemically significant for the rsETH market.

KelpDAO alleged that a North Korean hacking group attacked the bridge. The protocol also claimed LayerZero failed to prevent infiltration of its security infrastructure, which KelpDAO says allowed attackers to exploit alleged weaknesses in the universal bridge. Those claims will now be tested through the legal process, with KelpDAO seeking to hold LayerZero and Pellegrino accountable for the harm it says was inflicted on both the protocol and the wider DeFi ecosystem.

The attack’s size and timing gave it outsized impact. In DeFi, confidence can weaken quickly when users question the safety of bridges, lending pools, collateral systems, or wrapped assets. Because rsETH is connected to liquid staking and restaking activity, the exploit raised concerns beyond a single protocol and intensified scrutiny of how cross-chain assets are secured when they move outside their native environment.

LayerZero CEO Calls the Lawsuit Meritless

Pellegrino responded quickly after the civil claim was filed in British Columbia, Canada. He said Evercrest, identified with KelpDAO, had filed a notice of civil claim against himself and LayerZero, and he rejected the allegations. Pellegrino called the claim meritless and said he would meet the plaintiffs in Vancouver and defend himself accordingly.

The response signals that LayerZero does not intend to accept KelpDAO’s framing of the exploit. In public disputes following major hacks, responsibility is often contested among protocol developers, bridge providers, external auditors, validators, infrastructure partners, and users. KelpDAO’s lawsuit argues that LayerZero’s technology and alleged disclosure failures were central to the attack. Pellegrino’s statement indicates that LayerZero will challenge that position in court.

The case could become an important reference point for how legal systems approach responsibility in decentralized infrastructure. Many DeFi arrangements operate through a mix of smart contracts, third-party integrations, governance structures, security assumptions, and cross-chain messaging systems. When an exploit occurs, the legal question of who had control, who had knowledge of risks, and who owed duties to users or partners can be difficult to answer.

DeFi Liquidity Shock Followed the Exploit

The fallout from the rsETH exploit extended into broader DeFi liquidity conditions. After the bridge was drained, pressure spread across stablecoin markets and lending venues. Aave, the largest decentralized finance lending pool, was forced to borrow $300 million to meet increasing user demand for asset withdrawals. That detail underscored how a bridge exploit can create second-order effects when users move quickly to reduce exposure, repay positions, withdraw collateral, or seek safer assets.

Days later, the exploit erased $20 billion in total value locked across decentralized finance deposits. Total value locked is widely used by market participants as a measure of how much capital is committed to DeFi protocols. While it does not capture every risk in the system, a sharp decline can indicate that users are pulling funds, reducing leverage, or losing confidence in key infrastructure.

For DeFi, the episode reinforced a familiar concern: liquidity is deeply interconnected. A vulnerability in one bridge can affect lending markets, stablecoin flows, restaking tokens, collateral values, and user behavior across multiple protocols. When a major cross-chain route is compromised, users may not wait for technical explanations before withdrawing funds or repositioning capital.

KelpDAO Says It Migrated rsETH Bridge Security

KelpDAO said it has taken action since the incident to ensure user assets are safe and protected. The protocol specifically pointed to migrating rsETH’s bridge to a more secure cross-chain security standard. The move suggests KelpDAO is trying to reassure users that it has changed its infrastructure following the exploit, while also pursuing accountability through litigation.

Security migrations are common after major DeFi incidents, but they do not erase the financial and reputational damage caused by an exploit. Users often want to know whether assets are protected going forward, whether losses can be recovered, and whether the parties involved will disclose enough information for the market to understand what went wrong. KelpDAO’s public position is that it must both protect users and correct the record regarding responsibility for the attack.

The protocol said LayerZero and Pellegrino had publicly blamed KelpDAO for their failures over the last few months. That accusation points to a broader communications battle between the parties, one that now moves into a legal venue. For market participants, the courtroom process may bring more attention to technical design choices, risk warnings, operational security, and the duties of infrastructure providers in cross-chain DeFi.

Why Cross-Chain Bridges Remain a DeFi Flashpoint

Cross-chain bridges are essential to multi-chain crypto activity, but they remain one of the most sensitive areas in decentralized finance. Unlike a simple token transfer within a single blockchain, cross-chain movement typically requires some form of messaging, verification, custody, minting, burning, or liquidity management between networks. Each layer creates potential risk if assumptions fail or if attackers find a way to manipulate the system.

The KelpDAO dispute highlights why bridge integrations are closely watched by technical traders, protocol teams, and institutional observers. When bridge infrastructure supports a large share of a token’s circulating supply, the consequences of a failure can be magnified. A drain involving nearly a fifth of circulating supply is not only a security issue; it can become a liquidity, pricing, governance, and confidence issue for the asset involved.

The allegations also arrive at a time when liquid staking and restaking protocols have become major parts of Ethereum-linked DeFi activity. These systems can improve capital efficiency, but they can also introduce additional layers of complexity. Tokens representing staked or restaked positions often rely on integrations across lending pools, bridges, and liquidity venues. That interconnected structure can amplify stress when one component fails.

The lawsuit may carry implications beyond KelpDAO and LayerZero. If courts are asked to evaluate whether a cross-chain infrastructure provider failed to disclose weaknesses or failed to prevent security infiltration, the result could influence how DeFi protocols document risks and negotiate integrations. Even before any judgment, the case may push teams to be more explicit about security models, incident response responsibilities, and liability assumptions.

Crypto infrastructure providers often operate in a fast-moving environment where open-source software, decentralized governance, and commercial partnerships overlap. Market participants may expect high levels of transparency, while providers may argue that some technical details are complex, evolving, or dependent on integration decisions made by others. The KelpDAO case brings those tensions into focus because it asks who should bear responsibility when a major exploit occurs through shared infrastructure.

For now, the claims remain contested. KelpDAO says LayerZero’s alleged failures enabled the exploit and harmed the broader DeFi ecosystem. Pellegrino says the claim is meritless and has pledged to defend himself and LayerZero. Until the legal process advances, the case is likely to remain a flashpoint for debates over bridge security, DeFi accountability, and how risk should be allocated across interconnected crypto systems.

Frequently Asked Questions (FAQs)

What is KelpDAO suing LayerZero over?

KelpDAO is suing LayerZero and co-founder Bryan Pellegrino over a $292 million exploit that drained rsETH from KelpDAO’s cross-chain bridge. KelpDAO alleges that undisclosed weaknesses in LayerZero’s technology enabled the attack.

How much rsETH was drained in the exploit?

The April 22 attack drained 116,500 rsETH. The stolen tokens were valued at roughly $292 million, making the incident one of the largest DeFi exploits of the year so far.

What did KelpDAO allege against LayerZero?

KelpDAO alleged that LayerZero failed to disclose weaknesses and risks in its own technology and failed to prevent infiltration of its security infrastructure. KelpDAO says those failures allowed attackers to exploit the bridge.

How did Bryan Pellegrino respond?

Bryan Pellegrino called the claim meritless and said he would defend himself and LayerZero in British Columbia, Canada. His response indicates LayerZero disputes KelpDAO’s allegations and will contest them in court.

Was a hacking group linked to the attack?

KelpDAO said a North Korean hacking group allegedly attacked its cross-chain bridge. The allegation remains part of the broader dispute surrounding how the exploit occurred and who should be held responsible.

Why did the exploit affect the wider DeFi market?

The exploit triggered concerns about liquidity, collateral safety, and bridge security across decentralized finance. It contributed to pressure in stablecoin markets and forced Aave to borrow $300 million to meet rising withdrawal demand.

What happened to DeFi total value locked after the incident?

Days after the exploit, $20 billion in total value locked was erased from decentralized finance deposits. The decline showed how quickly confidence can weaken when a major cross-chain system is compromised.

What has KelpDAO done since the attack?

KelpDAO said it has taken steps to protect user assets, including migrating rsETH’s bridge to a more secure cross-chain security standard. The protocol is also pursuing legal action to hold LayerZero and Pellegrino accountable.

Why are cross-chain bridges considered risky?

Cross-chain bridges connect assets and messages across blockchains, which can require complex verification and security assumptions. If weaknesses exist in the bridge design or operations, a failure can spread across multiple DeFi markets.