Mastodon Skip to content
LIVE - NYSE/-/- CRYPTO/OPEN/24/7
BTC$83,872▼ 0.53%ETH$2,684▼ 0.03%SOL$121.32▲ 4.04%TOTAL CRYPTO$2.89T▼ 2.74%S&P 5007,743.41▲ 0.86%NASDAQ27,068.72▲ 3.51%DOW51,828.62▼ 3.26%GOLD4,320.50▼ 7.97%WTI92.44▲ 12.24%BRENT97.47▲ 10.04%EUR/USD1.1392▼ 2.37%USD/JPY157.19▼ 1.23%DXY101.04▲ 2.14%
Crypto

KelpDAO Sues LayerZero Over $292M rsETH Bridge Exploit

The restaking protocol filed suit against LayerZero and co-founder Bryan Pellegrino, blaming undisclosed weaknesses for April's $292 million bridge hack.

Pexels – RDNE Stock project

KelpDAO has filed a lawsuit against LayerZero and its co-founder Bryan Pellegrino, blaming the cross-chain messaging protocol for the largest DeFi exploit of 2026, a $292 million attack that drained its rsETH bridge in April. The suit, announced in a post on X on Thursday and reported by CoinDesk, alleges that undisclosed weaknesses in LayerZero’s protocol enabled the April 22 attack, which siphoned 116,500 rsETH, roughly a fifth of the restaked token’s circulating supply at the time.

Pellegrino pushed back within hours. He called the lawsuit meritless and said he would defend himself and LayerZero in a British Columbia court, where the filing was made. The dispute sets up one of the most closely watched legal fights in decentralized finance, with a protocol operator arguing that the infrastructure provider it built on owed it stronger security assurances.

What happened in April

The April 22 attack hit KelpDAO’s cross-chain bridge, which used LayerZero for message verification between networks. Attackers, whom KelpDAO has linked to a North Korean hacking group, exploited the setup to mint and drain rsETH on one chain while the bridge failed to validate the corresponding burn on another. The stolen tokens were dumped across decentralized exchanges, and the drain contributed to a broader liquidity crisis that erased an estimated $20 billion in decentralized finance deposits as protocols pulled back and users rushed to exit.

Restaking protocols like KelpDAO let holders of liquid staking tokens earn additional yield by securing other networks. rsETH is the protocol’s restaked receipt token, and the bridge was the mechanism for moving it between chains. After the exploit, KelpDAO moved to contain the damage, pausing affected routes and working with exchanges to freeze portions of the stolen funds, though most of the haul was never recovered.

The scale of the loss placed the incident among the largest bridge exploits on record. Bridges concentrate value at a single point of verification, which is why they have historically attracted the biggest thefts in the industry, from the Ronin Bridge hack in 2022 to repeated attacks on multichain routers. KelpDAO’s case adds a new dimension: rather than accepting the loss as an operational failure, it is assigning legal responsibility to a third-party infrastructure provider.

The legal argument

KelpDAO’s core claim is that LayerZero and Pellegrino failed to disclose weaknesses in the cross-chain protocol that the bridge depended on, and that those weaknesses made the exploit possible. The suit frames the relationship as one where an infrastructure provider’s representations about security mattered to the protocols building on top of it. LayerZero is one of the most widely used cross-chain messaging systems in crypto, connecting dozens of bridges and applications, which is why the case has drawn attention well beyond the two parties involved.

Legal observers note the case will test how far responsibility for bridge security extends up the stack. Bridges have been crypto’s most-attacked infrastructure category for years, with exploits routinely running into nine figures. Most post-mortems blame the bridge operator or its key management. This suit instead targets the messaging layer underneath, a novel theory that could reshape how protocols evaluate and contract for cross-chain infrastructure.

A bad stretch for bridge security

The filing lands during a rough stretch for exchange and bridge security generally. On September 24, Bitget lost $351.6 million in an overnight hack that its CEO attributed to spoofed transfers through a compromised wallet backend, and a smaller crypto casino, Duelbits, went offline after a $7 million hot-wallet theft the same week. The Liquid Network also paused operations this month after purported white-hat hackers withdrew roughly $320 million in bitcoin, though the attackers later said they would return most of the 4,000 BTC after a bug fix.

North Korean groups remain the most prolific actors in this space. Analysts attribute several billion dollars in annual crypto thefts to Lazarus and affiliated units, with proceeds historically funding state programs. KelpDAO’s attribution of the April attack to such a group fits a pattern in which high-value bridges and exchanges are targeted by state-linked teams with patience and resources that most criminal hackers lack.

For KelpDAO, the lawsuit is also about recovering losses. The protocol’s treasury and its users absorbed the bulk of the $292 million hit, and insurance or compensation mechanisms in decentralized finance remain thin. A court award, even against a well-funded defendant, would be a first of its kind in this corner of the industry.

What comes next

The case was filed in British Columbia, where Pellegrino is reported to reside, and he has already signaled he will contest it. Cross-border litigation involving decentralized protocols raises awkward questions for courts, from service of process on pseudonymous teams to how judges treat smart-contract code as a product with warranties. The outcome will take years, but the industry will be watching the early motions closely, since a ruling on whether infrastructure providers owe disclosure duties to downstream protocols would set a precedent for every bridge and messaging layer in the market.

The timing also matters for LayerZero commercially. The company has been courting institutional partners and expanding into tokenized asset transfers, and a public lawsuit alleging undisclosed security weaknesses arrives at an awkward moment for that pitch. LayerZero’s messaging layer underpins a significant share of cross-chain volume, and counterparties now have a documented dispute to point to when negotiating security terms.

For the restaking sector, the suit is another reputational drag in a difficult year. Restaking grew quickly on the promise of stacking yield on top of staked ether, but the April exploit showed how quickly a single infrastructure failure can cascade through dependent protocols. Deposits across the sector remain well below their early-2026 peaks, and operators have been working to rebuild confidence through audits, bug bounties and clearer risk disclosures.

SourcesCoinDesk, September 25, 2026; KelpDAO statement on X; CoinDesk coverage of the April 22 exploit.
Share: X