BREAKING
Sep 27KelpDAO Is Suing LayerZero for the $292M Hack. Its Evidence: LayerZero Signed Off on the Exact Setup That Got Drained●Sep 26The SEC Is About to Be Two People. 'Crypto Mom' Hester Peirce Just Quit, and Nobody Has Been Nominated to Replace Her●Sep 25Hackers Took $351.6M From Bitget Without Stealing a Single Private Key. They Forged the Transfer Orders and Bitget's Own Signing Machines Approved Them●Sep 24BitMEX Invented the 100x Perpetual Swap, Beat a Criminal Case With a Presidential Pardon, Then Lost to the Product It Created. Leave Money There Now and It Costs You $50 a Month●Sep 23Circle Pays Binance Every Month to Push USDC. Now Binance Owns $100M of Circle, and the Filing Landed the Same Day the Sanctions Probe Leaked●Sep 22Last Week Manhattan Prosecutors Moved to Seize $61M of Iranian Oil Money That Ran Through Binance. This Week They're Investigating Binance●Sep 21Polymarket's Payment Processor Was Rejecting 80% of US Deposits as Fraud. The CEO's Reported Answer: Keep Growing, Pay the Fine Later●Sep 20Robinhood Wallet Users Bought Dogwifhat With Credit Cards and Earned Cash Back, Because Visa Was Told They Were Buying E-Books●Sep 19The Senate Needed 60 Votes to Give Crypto a Rulebook and Got 49. The CFTC Needed Zero, and Just Filed One With the White House.●Sep 18The SEC Just Legalized Trading Apple Stock on Uniswap. The $3 Billion of Tokenized Stocks That Already Exist Don't Qualify.●Sep 27KelpDAO Is Suing LayerZero for the $292M Hack. Its Evidence: LayerZero Signed Off on the Exact Setup That Got Drained●Sep 26The SEC Is About to Be Two People. 'Crypto Mom' Hester Peirce Just Quit, and Nobody Has Been Nominated to Replace Her●Sep 25Hackers Took $351.6M From Bitget Without Stealing a Single Private Key. They Forged the Transfer Orders and Bitget's Own Signing Machines Approved Them●Sep 24BitMEX Invented the 100x Perpetual Swap, Beat a Criminal Case With a Presidential Pardon, Then Lost to the Product It Created. Leave Money There Now and It Costs You $50 a Month●Sep 23Circle Pays Binance Every Month to Push USDC. Now Binance Owns $100M of Circle, and the Filing Landed the Same Day the Sanctions Probe Leaked●Sep 22Last Week Manhattan Prosecutors Moved to Seize $61M of Iranian Oil Money That Ran Through Binance. This Week They're Investigating Binance●Sep 21Polymarket's Payment Processor Was Rejecting 80% of US Deposits as Fraud. The CEO's Reported Answer: Keep Growing, Pay the Fine Later●Sep 20Robinhood Wallet Users Bought Dogwifhat With Credit Cards and Earned Cash Back, Because Visa Was Told They Were Buying E-Books●Sep 19The Senate Needed 60 Votes to Give Crypto a Rulebook and Got 49. The CFTC Needed Zero, and Just Filed One With the White House.●Sep 18The SEC Just Legalized Trading Apple Stock on Uniswap. The $3 Billion of Tokenized Stocks That Already Exist Don't Qualify.●
BTC -- --%
ETH -- --%
Fear & Greed F&G 70 Greed
ESC
Type to search articles
KelpDAO Is Suing LayerZero for the $292M Hack. Its Evidence: LayerZero Signed Off on the Exact Setup That Got Drained
BREAKING

KelpDAO Is Suing LayerZero for the $292M Hack. Its Evidence: LayerZero Signed Off on the Exact Setup That Got Drained

In April, someone forged one cross-chain message and walked off with $292 million of restaked ETH. For five months, KelpDAO and LayerZero have argued in public about whose fault that was.

Now they’re arguing about it in court, and Kelp’s main exhibit is LayerZero’s own paperwork.

On September 25, Evercrest Technologies, the company behind KelpDAO, filed a notice of civil claim in the Supreme Court of British Columbia against LayerZero Labs Ltd., LayerZero Labs Canada Inc. and co-founder Bryan Pellegrino personally. The claims are negligent misrepresentation, negligence and defamation, and Kelp is asking for aggravated and punitive damages on top of ordinary damages.

The core allegation, according to The Block’s reading of the filing: LayerZero “reviewed and endorsed” Kelp’s bridge configuration in writing, then watched it get drained.

Quick Recap: One Verifier, One Forged Message

On April 18, an attacker drained 116,500 rsETH (about $292 million at the time) from Kelp’s LayerZero-powered rsETH bridge. It’s still one of the largest DeFi exploits of 2026. We covered the hack and the $300M DeFi United rescue that followed, after the stolen rsETH turned into bad debt at Aave, Compound and Euler.

The mechanics, per LayerZero’s own incident report:

  • On March 6, attackers socially engineered a LayerZero developer and got credentials that gave them access to LayerZero’s RPC infrastructure. (Kelp’s filing adds malware on the developer’s computer.)
  • On April 18, the compromised nodes fed false blockchain data to LayerZero’s verifier while the attackers disrupted external data providers.
  • The verifier approved a forged cross-chain message, and the bridge released rsETH that was never burned on the other side.

It worked because Kelp’s bridge ran a 1-of-1 DVN (decentralized verifier network) configuration: a single verifier, with no second, independent check that could have refused the forged message.

Everyone agrees on that much. The lawsuit is about who chose that setup.

Kelp’s Case: “You Told Us It Was Fine”

According to the filing as reported by The Block, Kelp alleges:

  • On February 2, 2024, LayerZero said there was “no problem” with the default DVN setup.
  • On March 21, 2024, LayerZero directed Evercrest to use the same 1-of-1 configuration as another bridge.
  • LayerZero warned at least one other developer, USDT0, about the risks of that kind of setup, but didn’t warn Kelp.
  • The attacker got in through LayerZero’s infrastructure, not Kelp’s.

Kelp’s summary: LayerZero “failed to disclose risks in its technology or prevent attackers from compromising its infrastructure,” and “had reviewed and endorsed its deployment and configuration in writing before the exploit.”

Kelp also says its bridge was following LayerZero’s documented defaults, and that the verifier it depended on was one LayerZero operated.

The defamation claim is the sharpest part. Since April, LayerZero has said publicly that Kelp’s configuration was the problem. Kelp is now effectively saying that blaming it for a setup LayerZero approved has damaged its reputation.

LayerZero’s Case: “We Told You to Diversify”

LayerZero has been consistent since April. Its position:

  • Kelp’s 1-of-1 verifier config was the single point of failure, and LayerZero calls it exactly that.
  • LayerZero recommended verifier diversification before the exploit.
  • Kelp manually switched to the 1-of-1 setup.

Pellegrino’s response to the suit was short: “The claim continues to be meritless,” and he said he’ll defend it in Vancouver. Nothing about that sounds like a settlement.

None of this has been tested in court yet. A notice of civil claim is one side’s allegations, and LayerZero hasn’t filed a defense.

Why This Case Is Bigger Than Kelp

DeFi has always worked on an unspoken deal: infrastructure providers ship modular, configurable security, and the integrator owns the config. If you choose one verifier instead of three, that’s your problem.

Kelp is testing whether that deal holds up when:

  1. the provider reviewed the config and put its approval in writing, and
  2. the breach came through the provider’s own infrastructure.

If a Canadian court finds a duty of care there, every bridge, oracle, restaking and messaging protocol that does “integration reviews” for partners inherits legal exposure. That changes how those reviews get done, who signs them, and what the documentation says.

If LayerZero wins, the lesson goes the other way: “the vendor said it was fine” won’t protect you. Integrators will have to own their security decisions in full, including the defaults.

In both cases, the industry has been assuming the answer to a legal question that a court may now actually decide.

Some context on what Kelp has done since the hack: it moved rsETH to Chainlink CCIP in May, shut down its sbUSD stablecoin product, committed 2,000 ETH to the recovery effort, and dealt with more than $650 million in user withdrawals after the exploit.

Why This Matters for Crypto Jobs

This lawsuit is basically a job description for roles the industry has under-hired for.

  • Bridge and interop security engineers. The whole case turns on one config parameter: how many verifiers. Teams that treated DVN settings, oracle quorums and multisig thresholds as “set once at deployment” will now want someone who owns them full time. Expect more job listings that mention cross-chain messaging (LayerZero, CCIP, Hyperlane, Wormhole) by name.
  • OpSec and infrastructure security. The attack started with one socially engineered developer, six weeks before the drain. Every protocol running its own nodes, RPCs or verifiers needs endpoint security, credential hygiene and insider-threat programs, all of which have been thin in crypto.
  • Integration and solutions engineers at infra companies. If “we reviewed your setup” can become a legal liability, infra providers will formalize their partner reviews with written risk disclosures, standard sign-offs and audit trails. Someone has to design that process and run it.
  • Crypto litigation and risk counsel. A negligence and defamation fight between two major protocols, in a Canadian court, over a hack attributed to a nation-state, is new territory. Law firms and in-house legal teams with smart-contract and security literacy will be in demand, and so will expert witnesses who can explain a DVN to a judge.
  • Security-minded DevRel and docs writers. Kelp’s argument leans heavily on what LayerZero’s documented defaults were. Documentation is now potentially evidence. Teams will want people who can write security guidance that’s clear, current and defensible.

After a $292M hack, the old answer to “whose fault was it?” was a Twitter thread. Now it’s a court filing, and that means more work for security, infrastructure and legal people.


Building bridges, securing infra, or want to move into crypto security? Find live openings for security engineers, protocol devs and crypto legal roles at Cryptogrind, which lists jobs in crypto and Web3.

How did this hit?

Discussion

Comments are powered by GitHub. Sign in with your GitHub account to chime in.

Related jobs on Cryptogrind

View all

Looking for your next crypto role?

Browse hundreds of Web3 and crypto positions on Cryptogrind — from smart contract engineers to DeFi analysts.

Browse jobs