- Due to the $292 million rsETH exploit, KelpDAO has sued Bryan Pellegrino and LayerZero.
- According to KelpDAO, the attack was facilitated by LayerZero infrastructure and verifier flaws.
- Citing its 1-of-1 DVN architecture as a major security issue, LayerZero refutes KelpDAO’s assertions.
KelpDAO said on September 24 that Evercrest Technologies Inc., the legal entity behind Kelp, filed the action over what it describes as failures linked to LayerZero’s infrastructure and verifier security.
Today we filed a lawsuit against LayerZero and its co-founder, Bryan Pellegrino, to right the wrongs associated with the exploit of rsETH’s LayerZero bridge earlier this year. For more details, please refer to the statement below.https://t.co/gPQTPeM0Zh
— Kelp (@KelpDAO) September 25, 2026
A months-long public discussion over the April rsETH exploit is transformed into a formal legal struggle by the lawsuit. No court has made a decision regarding the charges, and the accusations are still unsubstantiated.
Calling the accusations “meritless,” Pellegrino has refuted the case and stated he will defend LayerZero and himself in Vancouver.
KelpDAO Challenges LayerZero’s 1-of-1 DVN Claims
Kelp says LayerZero reviewed and approved the deployment and configuration in writing before the exploit. The protocol argues this conflicts with LayerZero’s later criticism that Kelp relied on a risky 1-of-1 Decentralized Verifier Network (DVN) setup.
LayerZero has maintained that Kelp’s configuration created a single point of failure. The April incident analysis said the bridge used one DVN, meaning there was no independent verifier available to reject a fraudulent cross-chain message.
Kelp has disputed that account and previously said its bridge followed LayerZero’s documented defaults and relied on LayerZero-operated infrastructure.
LayerZero Infrastructure Was Compromised Before The Attack
LayerZero’s own May incident report said attackers compromised the infrastructure used by its DVN before the rsETH drain.
According to the report, the intrusion began after an attacker socially engineered a LayerZero developer and obtained session credentials. The attacker then accessed LayerZero’s RPC environment and manipulated internal RPC nodes.
During the April 18 exploit, the compromised infrastructure supplied false blockchain information. LayerZero’s DVN subsequently signed a forged message, allowing Kelp’s Ethereum bridge to release 116,500 rsETH without a corresponding burn on the source chain.
A second attempt involving 40,000 rsETH was blocked after Kelp paused its contracts.
Kelp Moves rsETH To Chainlink CCIP
Following the exploit, Kelp began moving the rsETH cross-chain infrastructure away from LayerZero and toward Chainlink CCIP. The protocol also participated in recovery efforts involving affected DeFi platforms after stolen rsETH was used as collateral in lending markets. LayerZero later ended support for 1-of-1 DVN configurations and pushed applications toward multi-verifier security models.
Stay informed with the latest trends in Web3, blockchain innovation, and cybersecurity updates at 3verseTV
You need to login in order to Like










Leave a comment