LayerZero faces lawsuit over $292 million rsETH exploit and alleged security disclosure failures

BlockchainCrypto Coin Show News Team·September 25, 2026·3 min read

KelpDAO has sued LayerZero and CEO Bryan Pellegrino over a $292 million exploit of its rsETH token in April, marking an escalation in a dispute that hinges on whether the bridge provider disclosed known security weaknesses. For institutional investors holding cross-chain assets or considering LayerZero infrastructure, the case frames a critical question: how liability for bridge exploits allocates between protocol designers and users when documented guidance conflicts with actual defaults.

  • KelpDAO alleges LayerZero failed to disclose security flaws and endorsed a risky 1-of-1 DVN configuration in writing before the April exploit.
  • LayerZero CEO Bryan Pellegrino confirmed the British Columbia lawsuit and said the claim is “meritless” and will be defended in court.
  • The dispute centers on whether a single-verifier setup followed LayerZero’s official documentation or violated the company’s stated best-practice recommendations.
  • $292M rsETH tokens drained in April exploit, largest crypto security breach until Bitget’s $351.6M hot wallet breach.
  • 1-of-1 Decentralized Verifier Network configuration that accepted forged cross-chain messages without independent verification.
  • May 6 date KelpDAO published report claiming its DVN setup followed LayerZero’s official defaults, not against guidance.

KelpDAO’s lawsuit against LayerZero and co-founder Bryan Pellegrino in British Columbia was disclosed in a statement posted on X on September 25, first reported by CryptoPotato, accusing the cross-chain bridge provider of concealing security weaknesses that enabled attackers to drain $292 million in rsETH tokens during an April exploit. The lawsuit represents KelpDAO’s most direct legal challenge to LayerZero after months of public dispute over whether the breach stemmed from LayerZero’s technology failures or KelpDAO’s misconfiguration.

KelpDAO Claims LayerZero Endorsed a Vulnerable Setup Before Approving Deployment

In a statement on X on September 25, KelpDAO alleged that LayerZero failed to disclose weaknesses in its technology and allowed infiltration of its security infrastructure. The protocol stated that LayerZero “reviewed and endorsed, in writing, our deployment and configuration of LayerZero’s technology,” directly contradicting LayerZero’s public stance that the attack exploited KelpDAO’s choice to use a 1-of-1 Decentralized Verifier Network configuration.

Under a 1-of-1 DVN setup, LayerZero’s own verifier served as the sole validator for cross-chain messages, creating a single point of failure where a forged message could pass without independent verification. The bridge operator had publicly recommended using multiple DVNs to prevent exactly such a vulnerability.

KelpDAO disputed that account in a May 6 report, arguing the 1-of-1 configuration reflected LayerZero’s official documentation and default deployment practices, not a departure from stated best practices.

Pellegrino Confirms Lawsuit and Vows to Defend in Court

Pellegrino confirmed the civil claim within hours on X, stating he will “meet them in Vancouver and defend myself accordingly” and characterizing the claim as “meritless.”

The case arrives as the largest crypto security incident of the year until Bitget’s $351 million hot wallet breach in September. Cyvers at the time of the KelpDAO exploit estimated $293.7 million in rsETH was drained, with assets moved to ETH across Ethereum and Arbitrum, affecting lending protocols including Aave V3, Compound V3, and Euler.

The dispute reflects a deeper tension in decentralized finance: who bears responsibility when a bridge’s documented guidance diverges from its default behavior.

The lawsuit will determine whether LayerZero’s written endorsement of KelpDAO’s configuration creates liability for the company, or whether users retain sole responsibility for infrastructure choices even when based on official documentation.

The CCS read. We note the case hinges on a documentary question, whether LayerZero’s written endorsement can be proven, rather than a technical one. If KelpDAO produces contemporaneous records showing explicit sign-off, institutional users and protocol designers will face pressure to obtain written exculpations for all non-standard configurations, shifting burden and operational friction upstream to bridge operators.

Watch for the filing of Pellegrino’s defense and LayerZero’s response in British Columbia courts; the outcome will signal whether bridge infrastructure providers face liability for deployment guidance, and may reshape how institutional protocols structure cross-chain collateral arrangements on multi-chain platforms.

Get this in your inboxThe Crypto Coin Show newsletter covers the policy and market moves institutional crypto investors are pricing in.

Subscribe