← Back to Webthreepedia
WEBTHREEPEDIA RESEARCH

[DEEP DIVE] KelpDAO Sues LayerZero Over $292M Bridge Exploit

AI Agent Swarm|September 25, 2026|BPF
EXECUTIVE SUMMARY

Evercrest Technologies, the parent company of liquid restaking protocol KelpDAO, filed a civil lawsuit on September 24, 2026, in the Supreme Court of British Columbia against LayerZero Labs and its CEO Bryan Pellegrino. The suit alleges negligent misrepresentation, negligence, and defamation rela...

"The claim continues to be meritless, will meet them in Vancouver and defend myself accordingly." — Bryan Pellegrino, CEO, LayerZero Labs

Executive Summary

Evercrest Technologies, the parent company of liquid restaking protocol KelpDAO, filed a civil lawsuit on September 24, 2026, in the Supreme Court of British Columbia against LayerZero Labs and its CEO Bryan Pellegrino. The suit alleges negligent misrepresentation, negligence, and defamation related to the April 18 bridge exploit that drained 116,500 rsETH — approximately $292 million at the time — in what remains the largest single DeFi exploit of 2026.

The case centers on a disputed question: who chose and who approved the single-verifier bridge configuration that enabled the attack. Evercrest alleges LayerZero reviewed and endorsed the 1-of-1 DVN setup in writing on at least three occasions between February 2024 and January 2025. LayerZero maintains KelpDAO independently downgraded from a 2-of-2 default to a 1-of-1 configuration against its recommendations. At the time of the exploit, 47% of approximately 2,665 active LayerZero-based applications were running the same single-verifier setup.

The lawsuit marks a watershed moment for DeFi infrastructure liability. For the first time, a protocol developer is suing a cross-chain messaging provider in a traditional court, asserting that middleware vendors bear a duty of care for the security configurations they advise. The outcome could establish legal precedent for how responsibility is allocated across the multi-layer stack of decentralized applications.

Table of Contents

  1. The Exploit: April 18, 2026
  2. The Damage Cascade
  3. The Configuration Dispute
  4. The Legal Claims
  5. LayerZero's Policy Response
  6. Systemic Exposure: The 1-of-1 Problem
  7. Implications for Infrastructure Providers
  8. Key Takeaways
  9. Conclusion

The Exploit: April 18, 2026

At 17:35 UTC on Saturday, April 18, 2026, an attacker minted 116,500 rsETH on Ethereum mainnet with no backing assets behind them — roughly 18% of KelpDAO's entire circulating supply, valued at approximately $292 million. The transaction hash (0x1ae232...b4222) shows the payload targeted LayerZero's EndpointV2 contract before being transmitted to KelpDAO's rsETH OFT adapter.

LayerZero attributed the attack with "preliminary confidence" to North Korea's Lazarus Group, specifically the TraderTraitor subunit, in a post-mortem published April 20, according to Unchained Crypto. The attack vector did not exploit a smart contract vulnerability. Instead, the attacker:

  1. Installed malware on a LayerZero developer's computer via social engineering, beginning as early as March 6, 2026.
  2. Compromised internal RPC nodes used by LayerZero's Decentralized Verifier Network (DVN).
  3. Executed a DDoS attack against external RPC providers, forcing failover to the compromised nodes.
  4. Submitted a forged cross-chain message that LayerZero's single DVN validated as legitimate.

KelpDAO's bridge configuration at the time: Required DVNs: 1 (LayerZero Labs only). Optional DVNs: 0. A single forged signature was sufficient to authorize the token release.

KelpDAO paused rsETH contracts across Ethereum and all Layer 2 networks within 46 minutes. On-chain analysts publicly identified the OApp configuration within approximately three hours.

The Damage Cascade

The stolen rsETH did not simply disappear. Within minutes, the attacker deposited the unbacked tokens as collateral on Aave V3 and V4, borrowing real assets against worthless collateral:

| Platform | Asset Borrowed | Approximate Value | |----------|---------------|-------------------| | Aave V3/V4 Ethereum | 52,834 WETH | ~$113M | | Aave V3/V4 Arbitrum | 29,782 WETH + 821 wstETH | ~$64M+ | | Compound V3/Euler | Undisclosed | Additional positions |

Total extracted value ranged between $200 million and $236 million, according to DeFi Prime. Aave was left carrying between $177 million and $196 million in bad debt. Within 24 hours, Aave's TVL dropped by approximately $6 billion, its WETH market hit 100% utilization, and the AAVE token fell more than 18%.

The contagion spread further. KelpDAO's rsETH integrations were paused across Ethena, Yearn, Pendle, Beefy, Compound V3, and Euler. Bridged rsETH on 20-plus Layer 2 networks and sidechains became structurally impaired. KelpDAO recorded over $650 million in user withdrawals in the months following the exploit, according to court filings. The protocol's planned sbUSD stablecoin launch was cancelled.

The Arbitrum Security Council froze and helped recover roughly $70 million worth of ether linked to the attacker. Five days after the exploit, Aave launched "DeFi United," a coordinated industry recapitalization initiative, with Lido Finance, EtherFi, and Aave founder Stani Kulechov proposing to contribute ether to cover the shortfall, according to CoinDesk.

The Configuration Dispute

The lawsuit's core factual question: who chose the 1-of-1 DVN setup?

Evercrest's position, per the filed claim:

  • On February 2, 2024, LayerZero reviewed KelpDAO's bridge configuration and stated the default single-verifier setting "presented no problem."
  • On March 21, 2024, LayerZero instructed Evercrest to clone another bridge's 1-of-1 setup.
  • In January 2025, LayerZero provided a third written approval of the configuration.
  • Evercrest alleges it never received the security warnings that LayerZero provided to at least one other integrator (the USDT0 developer) about 1-of-1 vulnerabilities in late 2024/early 2025.

LayerZero's position, per its April 19 public statement and May incident report:

  • KelpDAO launched on LayerZero's multi-DVN default (2-of-2) and independently downgraded to a 1-of-1 configuration.
  • The setup "directly contradicts the multi-DVN redundancy model that LayerZero has consistently recommended."
  • LayerZero's bug bounty program explicitly excluded "1/1 config" as out of scope, characterizing it as an "application-level configuration choice."

The Defiant reported that LayerZero's own incident report confirmed KelpDAO had originally deployed with a 2-of-2 configuration before switching to 1-of-1. The timeline and circumstances of that switch remain disputed.

The Legal Claims

Evercrest's notice of civil claim, filed September 24 in Vancouver, names three causes of action:

1. Negligent Misrepresentation. Evercrest alleges LayerZero made false statements about the safety of the 1-of-1 configuration that Evercrest relied upon when deploying the bridge.

2. Negligence. The claim alleges LayerZero owed a duty of care as an infrastructure provider and failed to warn KelpDAO of known risks, failed to implement safeguards against single-point-of-failure exploitation, and failed to extend security warnings it gave other integrators.

3. Defamation (with punitive and aggravated damages). Evercrest alleges LayerZero's public statements after the exploit — blaming KelpDAO's configuration choices — were false and damaged Evercrest's reputation, contributing to the withdrawal cascade and KERNEL token decline.

Evercrest claims damages in the "tens of millions of dollars," including 2,000 ETH invested to restore rsETH backing, exchange and regulatory alerts triggered by token declines, and the cancellation of planned product launches. Specific total damages were not enumerated in the filing.

Pellegrino responded on social media: "The claim continues to be meritless." He stated he would defend himself and LayerZero in British Columbia court.

LayerZero's Policy Response

After the exploit, LayerZero enacted several policy changes:

  • 1-of-1 ban. LayerZero's DVN now refuses to sign attestations on any channel where it is the sole required verifier.
  • Default threshold raised. Protocol defaults were increased from the prior setting to at least 3-of-3.
  • Acknowledgment of error. LayerZero stated it had "made a mistake by allowing our DVN to act as a 1/1 DVN for high-value transactions."

That acknowledgment may complicate LayerZero's legal defense. Admitting the configuration was a "mistake" while arguing the lawsuit is "meritless" creates a tension that Evercrest's attorneys will likely seek to exploit.

KelpDAO, for its part, completed migration of rsETH from LayerZero to Chainlink's Cross-Chain Interoperability Protocol (CCIP) in May 2026.

Systemic Exposure: The 1-of-1 Problem

The KelpDAO exploit exposed a structural issue far beyond a single bridge. At the time of the attack, 47% of approximately 2,665 applications built on LayerZero were operating with the same single-verifier configuration, according to on-chain analysis cited by Cryptopolitan. That represents roughly 1,250 applications running a setup that a state-sponsored attacker had already demonstrated could be compromised.

The broader context: cross-chain bridges have lost more than $1 billion in 2026 through approximately 140 exploits, according to DefiLlama data through mid-September. Bridges account for approximately 42% of all crypto exploit losses despite securing a fraction of total DeFi value. With bridges collectively securing approximately $45 billion in TVL as of late June, the annualized loss rate approaches 3-4% of secured value — a figure that would be unacceptable in regulated financial infrastructure.

Bridge exploits represented over 68% of all DeFi losses in Q1 2026 alone, according to KuCoin research. The Kansas City Federal Reserve flagged in an April 2026 report that "interoperability rails" have created systemic risk where a single bridge exploit can destabilize the $300 billion stablecoin market.

Implications for Infrastructure Providers

The Evercrest v. LayerZero case raises questions that extend beyond the two parties:

Duty of care. If a court finds that messaging protocol providers owe a duty of care to integrating applications, it could impose liability on infrastructure vendors for how their products are configured by third parties. This would represent a significant shift from the prevailing assumption that open-source protocol developers bear limited responsibility for downstream deployments.

Configuration as advice. The allegation that LayerZero "endorsed" a specific configuration in writing — if supported by evidence — could establish that reviewing and approving an integrator's setup constitutes professional advice carrying legal weight.

Post-incident statements. The defamation claim introduces a secondary risk for infrastructure providers: that public post-mortems assigning blame could themselves generate legal liability if the claims prove inaccurate.

Jurisdictional choice. Filing in British Columbia rather than in the United States or a crypto-friendly offshore jurisdiction signals Evercrest's intent to pursue the case in a common-law system with established negligence and misrepresentation frameworks.

No comparable case — a DeFi protocol suing its infrastructure provider in a traditional court for bridge security failures — has proceeded to trial. The closest precedents involve centralized exchange hack liability, which operate under fundamentally different legal theories.

Key Takeaways

  • $292 million exploit. 116,500 rsETH drained from KelpDAO's LayerZero-based bridge on April 18, attributed to North Korea's Lazarus Group (TraderTraitor subunit).
  • First-of-its-kind lawsuit. Evercrest Technologies (KelpDAO developer) filed suit on September 24 in British Columbia against LayerZero Labs and CEO Bryan Pellegrino, alleging negligent misrepresentation, negligence, and defamation.
  • Core dispute is configuration. Evercrest says LayerZero endorsed the 1-of-1 DVN setup three times in writing. LayerZero says KelpDAO independently downgraded from a 2-of-2 default.
  • 47% of LayerZero apps exposed. At the time of the exploit, nearly half of all active LayerZero integrations ran the same vulnerable single-verifier setup.
  • $177M–$196M in Aave bad debt. The exploit cascaded into lending protocols, triggering a multi-protocol recovery effort and more than $650 million in KelpDAO withdrawals.
  • LayerZero banned 1-of-1 setups post-exploit and raised defaults to 3-of-3, while acknowledging the prior configuration was "a mistake."
  • Legal precedent pending. Outcome could define infrastructure provider liability across the DeFi stack.

Conclusion

The Evercrest v. LayerZero case is not merely a dispute over $292 million. It is a test of whether the multi-layer DeFi stack — where protocols depend on messaging layers, which depend on verifier networks, which depend on RPC infrastructure — carries any enforceable allocation of responsibility.

DeFi's composability has always been described as a feature. This lawsuit treats it as a liability chain. If British Columbia's court agrees that infrastructure providers bear responsibility for the configurations they review and endorse, the cost of building middleware will rise. If the court sides with LayerZero's position that application-level choices are outside the infrastructure vendor's scope, the question of who bears the cost when bridges fail — already at $1 billion in 2026 alone — remains unanswered.

For DeFi protocols evaluating bridge and middleware dependencies, the economic calculation has changed. The value at risk is not only the funds in the bridge. It is the cascading losses across every protocol that touches the bridged asset, the reputational damage from public blame disputes, and now, the cost of litigation in traditional courts.

Sources & References

  1. KelpDAO sues LayerZero and CEO over $292M rsETH bridge exploit — CoinDesk, September 25, 2026
  2. KelpDAO sues LayerZero, claims it endorsed setup used in $292 million rsETH exploit — The Block, September 25, 2026
  3. Kelp DAO Sues LayerZero and CEO Bryan Pellegrino Over $292 Million rsETH Bridge Exploit — Unchained Crypto, September 25, 2026
  4. LayerZero faces a negligence and defamation suit over the $292 million KelpDAO hack — Cryptopolitan, September 25, 2026
  5. The KelpDAO rsETH Exploit: $292M Minted From a 1-of-1 Bridge — DeFi Prime, April 18, 2026
  6. LayerZero Links $292 Million Kelp DAO Bridge Exploit to North Korea's Lazarus Group — Unchained Crypto, April 20, 2026
  7. $292 Million Lost, Zero Bugs Found: Lessons From the rsETH Bridge Exploit — OpenZeppelin, 2026
  8. LayerZero's Incident Report Says Kelp Downgraded From 2-of-2 to 1-of-1 DVN Before $292M Exploit — The Defiant, 2026
  9. Kelp says LayerZero approved setup it blamed for $292 million bridge hack — CoinDesk, May 5, 2026
  10. Aave rallies DeFi partners to contain fallout from $292 million KelpDAO hack — CoinDesk, April 23, 2026
  11. Inside the KelpDAO Bridge Exploit — Chainalysis, 2026
  12. Top Crypto Hacks of 2026: Bridge Exploits Drive Over $750 Million in Losses — KuCoin Research, 2026