KelpDAO Takes Layerzero to Court Over a $292M Bridge Blowup
Five months after attackers tricked a Layerzero-powered bridge into releasing 116,500 rsETH worth about $292 million without a matching burn, the fight over who was responsible has landed in court. Evercrest Technologies, the company behind KelpDAO, filed a civil claim in British Columbia against Layerzero Labs and CEO Bryan Pellegrino. The money moved in one block. Figuring out who should foot the bill may take considerably longer.

Key Takeaways
- Kelp says LayerZero’s bridge released 116,500 rsETH worth about $292 million on April 18.
- Aave faced $123.7M-$230.1M in estimated bad debt after the Kelp rsETH exploit.
- Kelp sued LayerZero on Sept. 24; Pellegrino calls the civil claim “meritless.”
Five months ago, a bridge carrying KelpDAO’s rsETH received a message that appeared to say 116,500 tokens had been burned on another blockchain. They hadn’t. The bridge believed the message anyway and released roughly $292 million worth of rsETH on Ethereum in a single block. The attacker promptly put much of it to work borrowing real assets from Aave.
Now the companies behind the machinery are headed to court. On Sept. 24, Evercrest Technologies Inc., the company behind Kelp, filed a civil claim in British Columbia against Layerzero Labs and its CEO, Bryan Pellegrino, turning a months-long blame game into a legal fight over one deceptively simple question: Who owned the weak link?
“Today we filed a lawsuit against Layerzero and its co-founder, Bryan Pellegrino, to right the wrongs associated with the exploit of rsETH’s Layerzero bridge earlier this year,” the KelpDAO X account wrote. “As alleged in our lawsuit, the exploit was a direct result of LayerZero’s failures – including a failure to disclose weaknesses and risks inherent in LayerZero’s own technology, and a failure to prevent an infiltration of LayerZero’s own security infrastructure, which allowed attackers to exploit those weaknesses.”
One Message Unlocked $292 Million
The trouble started at 17:35 UTC on April 18. Kelp’s rsETH used Layerzero technology to move between blockchains. Its Unichain-to-Ethereum route relied on what is known as a 1-of-1 decentralized verifier network, or DVN. In plain English, one verifier stood between an incoming message and the release of tokens.
That verifier was supposed to make sure rsETH had actually been burned or locked on the originating chain before an equivalent amount was released on Ethereum. Attackers found a way around that check.
A forged packet was verified, committed and delivered on Ethereum. The bridge’s adapter released 116,500 rsETH even though no corresponding burn had occurred. Its balance fell from 116,723 rsETH to just 223 rsETH in one block. Roughly 18% of the circulating rsETH supply had effectively walked out the door. Not exactly pocket change. Bridge exploits then became a central theme in May.
The Contracts Did What They Were Told
The strange part is that Kelp’s token contracts apparently didn’t malfunction. Chainalysis found that the lie occurred off-chain. Layerzero later said an attacker socially engineered one of its developers on March 6, stole session credentials and entered the company’s RPC cloud. RPC infrastructure is essentially the plumbing software uses to ask a blockchain what happened.
The attackers allegedly poisoned internal nodes used by Layerzero’s verifier. Then, on April 18, external RPC providers were hit by a distributed denial-of-service attack, pushing the verifier toward the compromised nodes. Those nodes supplied false information indicating a legitimate burn had occurred. With only one verifier checking the message, there was no second opinion.
The forged packet got the green light. Layerzero’s later incident report, citing work from Mandiant and Crowdstrike, attributed the intrusion to Trader-Traitor, also known as UNC4899, a North Korea-linked cluster associated with the broader Lazarus Group. That attribution remains an intelligence assessment rather than a finding in the British Columbia civil case.
Then Aave Took It on the Chin
The attacker split the newly released rsETH among seven addresses and deposited about 89,567 rsETH into Aave V3 on Ethereum and Arbitrum. That counterfeit backing suddenly became collateral for real loans. The attacker borrowed roughly 82,650 wrapped ether (WETH) and 821 wrapped staked ether (wstETH). Aave’s Protocol Guardian began freezing rsETH and wrsETH reserves around 19:00 UTC.
Kelp paused contracts about 46 minutes after the first drain and stopped a second forged packet involving roughly 40,000 rsETH, worth an estimated $95 million to $100 million. The first one was enough. Estimates of Aave’s resulting bad debt ranged from $123.7 million to $230.1 million depending on how the losses were ultimately socialized.
At the time, Defillama data showed decentralized finance (DeFi) total value locked (TVL) falling by more than $14 billion in the days following the exploit, while Binance Research later linked April’s wider exploit wave, including Kelp, to about $13 billion in DeFi outflows. By then, the heat was on.
The $292 Million Question: Whose Fault Was It?
Layerzero and Kelp agree on plenty of the underlying mechanics. They sharply disagree on who bears responsibility for them. Layerzero has acknowledged that its RPC environment was compromised, but it has also pointed to Kelp’s 1-of-1 verifier configuration as the single point of failure. The company says it had recommended configurations using multiple verifiers.
Kelp tells a different story. It says the 1-of-1 setup was Layerzero’s documented default, that Layerzero reviewed and approved Kelp’s deployment in writing and that Kelp was told the defaults were fine. Kelp has also cited Dune figures indicating roughly 47% of Layerzero applications, representing more than 1,200 contracts, used the arrangement.
That disagreement sits at the heart of the new civil claim. Kelp alleges Layerzero failed to disclose technological risks, failed to prevent attackers from compromising infrastructure used by its verifier and had approved Kelp’s configuration before the exploit. Pellegrino has called the claim “meritless” and said he will defend himself and Layerzero in Vancouver. No court has decided who is right.
“Evercrest (KelpDAO) filed a notice of civil claim today in BC against myself and LZ. The claim continues to be meritless, will meet them in Vancouver and defend myself accordingly,” Pellegrino wrote.
Layerzero Later Changed the Rules
What happened after the exploit adds another wrinkle. Layerzero moved away from supporting 1-of-1 DVN configurations for high-value transfers and toward multi-verifier defaults. On May 8-9, the company apologized for its communications and said it “made a mistake by allowing our DVN to act as a 1/1 DVN for high-value transactions.”
That was not an admission that Layerzero is legally liable for Kelp’s losses. It does, however, put an awkward fact on the table: The configuration at the center of the fight is one Layerzero itself later said should not have been allowed for high-value transfers. Kelp went further and changed horses.
In early May, it announced plans to move rsETH away from Layerzero’s OFT system to Chainlink’s CCIP and CCT infrastructure. Solv Protocol and other projects also shifted substantial assets away from Layerzero after the incident. Meanwhile, the recovery effort spread well beyond Kelp.
Arbitrum’s Security Council froze about 30,765.67 ETH, then worth roughly $71 million, linked to the exploiter. Industry participants, including Aave, Lido, Ether.fi, Ethena, Mantle, Consensys, and Joe Lubin organized recovery support through DeFi United. By late May, Kelp said its final recovery tranche had moved, and minting, redemptions and bridging were back.
Now the Paper Trail Gets Its Day in Court
The Vancouver case changes the venue, not yet the facts. The claim is listed at Vancouver Law Courts under file number 267169, but the full notice of civil claim has not been made publicly available. That means the precise causes of action and amount of damages Kelp is seeking have not been independently verified.
What the lawsuit can do is put the paper trail under a microscope. Kelp says Layerzero approved its configuration in writing. Layerzero says Kelp chose a setup with one verifier despite recommendations favoring multiple checks. A court can compel documents, examine those communications, and determine what legal duties each side actually carried.
That question reaches beyond one $292 million bridge exploit. DeFi increasingly depends on layers of outside infrastructure that tell smart contracts what happened somewhere else. The contracts may be flawless and still act on a lie if the machinery feeding them information is compromised.
On April 18, one verifier believed such a lie, and 116,500 rsETH appeared on the Ethereum blockchain without being burned anywhere else. The technology took one block to make its decision. A judge now gets the once-over.
