KelpDAO Sues LayerZero and CEO Bryan Pellegrino Over $292M rsETH Exploit - Blockonomi
by Brenda Mary · BlockonomiTLDR:
Table of Contents
- TLDR:
- KelpDAO Takes $292 Million in rsETH Dispute to Court
- LayerZero and KelpDAO Disagree Over Bridge Security
- KelpDAO Moves rsETH Away From LayerZero Infrastructure
- Evercrest filed a civil claim against LayerZero and Bryan Pellegrino over April’s $292 million rsETH exploit.
- KelpDAO alleges LayerZero failed to disclose risks despite reviewing and approving its bridge configuration.
- LayerZero argues KelpDAO’s 1-of-1 verifier setup created the key security weakness behind the exploit.
- KelpDAO is migrating rsETH cross-chain transfers to a new security framework following the bridge attack.
Evercrest Technologies, the entity associated with KelpDAO, has sued LayerZero and CEO Bryan Pellegrino in British Columbia. The case centers on April’s rsETH bridge exploit, which drained about 116,500 rsETH, worth $292 million. KelpDAO alleges LayerZero failed to disclose security risks, while Pellegrino has called the claims “meritless.”
KelpDAO Takes $292 Million in rsETH Dispute to Court
The civil claim escalates a dispute that began after the April 18 attack on KelpDAO’s LayerZero-powered bridge. KelpDAO alleges failures within LayerZero’s security infrastructure contributed to the loss.
KelpDAO also alleges LayerZero failed to adequately disclose weaknesses linked to its technology before the attack. The complaint says LayerZero had reviewed and approved KelpDAO’s bridge deployment and configuration in writing.
LayerZero and Pellegrino dispute that account of responsibility. Pellegrino called the lawsuit “meritless” and said he plans to defend the case in Vancouver.
The court has not determined responsibility for the exploit, and the allegations remain subject to legal proceedings. The case now moves the months-long dispute from public statements into a Canadian courtroom.
LayerZero and KelpDAO Disagree Over Bridge Security
The April attack began after an attacker socially engineered a LayerZero developer and obtained session credentials. The attacker then entered LayerZero’s RPC cloud environment and compromised internal nodes. LayerZero reported these findings in its final investigation.
The compromised nodes supplied false blockchain information to LayerZero’s Decentralized Verifier Network. A denial-of-service attack also disrupted an external RPC provider used by the verification system.
KelpDAO’s rsETH bridge used a 1-of-1 DVN configuration, meaning one verifier could approve cross-chain messages. The compromised verifier approved a message claiming rsETH had been burned on another chain.
No corresponding burn had occurred, but the Ethereum-side contract released 116,500 rsETH to the attacker. Chainalysis described the incident as an attack against off-chain infrastructure rather than the bridge’s smart contract code.
LayerZero argues the single-verifier design created the critical failure point and says it had recommended stronger configurations. KelpDAO contests that position and points to LayerZero’s alleged approval of its setup.
KelpDAO Moves rsETH Away From LayerZero Infrastructure
KelpDAO has since started moving rsETH cross-chain transfers to a different security framework. The protocol previously identified Chainlink CCIP as the replacement for its LayerZero-based bridge.
Recovery efforts have also continued separately from the Canadian lawsuit. Authorities and ecosystem participants froze portions of the assets linked to the attacker after the April breach.
LayerZero’s investigation attributed the operation to TraderTraitor, a threat group associated with North Korea’s Lazarus Group. In addition, the independent researchers cited by LayerZero reached the same attribution.
The British Columbia case will now address competing claims over responsibility for the bridge’s design and compromised infrastructure. However, any allocation of legal liability remains for the court to determine.