KelpDAO Sues Over $292M Hack, Claims LayerZero Endorsed the Setup

KelpDAO filed a lawsuit claiming LayerZero endorsed a vulnerable setup in 2024. LayerZero says it always recommended the opposite. The hack cost $292M.

Jan Whitfield News

What KelpDAO Claims

Evercrest Technologies, KelpDAO's parent company, filed a lawsuit in British Columbia's Supreme Court on September 25 against LayerZero Labs and CEO Bryan Pellegrino. The claim centers on a February 2024 conversation. According to the filing, LayerZero told KelpDAO there was "no problem" with using a single decentralized verifier in its bridge configuration.

Two months later, on March 21, LayerZero allegedly directed Evercrest to use the same setup another bridge was running. That configuration left the bridge dependent on one verifier to authenticate cross-chain messages.

On April 18, 2026, an attacker gained control of that single verifier and drained 116,500 rsETH worth roughly $292 million. The restaking token was backed by staked Ethereum across multiple protocols. The attacker created a fake LayerZero packet claiming to originate from Unichain. No corresponding transaction existed on Unichain. The compromised verifier signed it anyway, and the bridge released the funds.

LayerZero's Position

LayerZero published its incident statement one day after the April hack. The company said its "express recommendation to all integrators" is to configure multiple verifiers with diversity and redundancy, not a single one.

Co-founder Bryan Pellegrino called the lawsuit "meritless" in a statement to The Block. LayerZero attributed the attack to North Korea's Lazarus Group and said the protocol itself functioned as intended. The company maintains that KelpDAO chose the single-verifier setup despite available alternatives.

The Technical Gap

A decentralized verifier network observes packets on one chain and delivers signed attestations to another. Only once the required verifiers have attested can the packet execute at the destination. KelpDAO's bridge required one signature. Zero optional verifiers were configured as backup.

That gave the attacker a single point of failure. Blockchain security firm Blockaid noted that moving to a two-of-N configuration would have blocked the synthetic packet. The second verifier would have rejected a message with no source transaction.

The lawsuit alleges negligent misrepresentation, negligence, and defamation. It claims the exploit was "a failure of LayerZero's own security infrastructure," not KelpDAO's systems. LayerZero disputes that characterization and says no vulnerability was identified in the protocol. The case will test where responsibility lands when an infrastructure provider reviews a customer's configuration and the customer later gets hacked.

The $292 million loss remains 2026's largest DeFi exploit. A second fraudulent packet targeting 40,000 more rsETH was blocked when KelpDAO's emergency multisig paused transfers about forty minutes after the first drain.

Disclaimer The information provided on Coinliva is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency investments are highly volatile and involve risk. While we strive to provide accurate and up-to-date information, some details may change over time. Always conduct your own research before making any financial decisions.