Kelp DAO has initiated legal action against LayerZero and co-founder Bryan Pellegrino, holding the cross-chain protocol responsible for the $292 million rsETH bridge exploit that took place in April.
The restaking protocol contends that LayerZero concealed vulnerabilities within its own technology and failed to prevent malicious actors from compromising its security infrastructure.
Inside the $292 Million rsETH Exploit
On April 18, attackers made off with roughly 116,500 units of rsETH—Kelp DAO’s liquid restaking token—via its LayerZero bridge. This incident stands as the biggest decentralized finance (DeFi) exploit of 2026. Afterwards, LayerZero attributed the breach to the Lazarus subgroup TraderTraitor.
According to LayerZero, the perpetrators hijacked a sufficient number of remote procedure call (RPC) nodes to supply fraudulent data to the bridge’s verifier. These specific servers function by relaying blockchain data to various applications.
Consequently, the verifier authorized an rsETH burn that had never actually occurred, leading the Ethereum contract to release funds against it.
On the other hand, LayerZero placed responsibility back onto Kelp’s configuration. The bridge depended entirely on a single verifier managed by LayerZero Labs, establishing a 1-of-1 setup.
The fallout rippled rapidly through the market. Aave experienced an $8.45 billion drop in total value locked (TVL) over a 48-hour span, while DeFi TVL saw widespread declines across major blockchains.
Kelp DAO Sues LayerZero After Months of Blame
Kelp asserts that LayerZero and Pellegrino spent months shifting the blame onto the protocol publicly. Conversely, the Kelp team maintains that LayerZero had officially reviewed and approved its deployment and configuration in writing.
Having made the complaint publicly available, the protocol seeks to hold LayerZero and Pellegrino accountable for the damage inflicted upon Kelp and the broader DeFi ecosystem.
The team emphasizes that user security continues to be its primary focus. Following the security breach, Kelp reports it has been transitioning the rsETH bridge to a safer cross-chain standard. Previously, the protocol identified competitor cross-chain messaging system Chainlink CCIP as its chosen replacement.
Efforts to recover the stolen capital have likewise moved into the legal arena. Back in May, a US court directive prohibited the Arbitrum DAO from transferring 30,766 ETH that it had frozen from the hacker.
Expressing eagerness for its day in court, Kelp DAO’s lawsuit against LayerZero could establish an early legal precedent regarding the accountability of infrastructure providers for security incidents occurring on client deployments.
Frequently Asked Questions
What caused the April rsETH exploit?
Attackers compromised remote procedure call (RPC) nodes to send false data to the bridge’s verifier, tricking it into approving an unperformed rsETH burn and releasing funds from the Ethereum contract.
How much money was stolen in the exploit?
Approximately 116,500 rsETH tokens, valued at $292 million, were drained in the April attack, making it the largest DeFi exploit of 2026.
Who has Kelp DAO sued over the incident?
Kelp DAO has filed a lawsuit against cross-chain protocol LayerZero and its co-founder, Bryan Pellegrino.
What new cross-chain standard is Kelp DAO adopting?
Kelp DAO has moved to transition its rsETH bridge to Chainlink CCIP, a rival cross-chain messaging system.
What happened to the frozen stolen funds?
A US court order issued in May blocked the Arbitrum DAO from transferring 30,766 ETH that had been frozen from the hacker.


