Five months after a forged cross-chain message drained $292 million from a restaking protocol, the fight over who pays for it has moved from Twitter threads into a courtroom. On September 25, 2026, Evercrest Technologies, the entity behind Kelp DAO, filed a civil claim in the Supreme Court of British Columbia against LayerZero Labs Ltd., LayerZero Labs Canada Inc., and LayerZero co-founder Bryan Pellegrino. The claim seeks damages, aggravated damages, and punitive damages tied to the April 18, 2026 exploit that emptied 116,500 rsETH from Kelp’s LayerZero-powered bridge.
The case matters beyond the dollar figure. For years, DeFi hacks have played out as a predictable script: a protocol gets drained, researchers trace the funds, and the loss gets written off as the cost of building on permissionless rails. Kelp DAO is trying to break that script by asking a real court to decide whether an infrastructure vendor, not just the anonymous attacker, owes money for a nine-figure loss. That question is now on file in Vancouver, and it could reshape how bridge providers, restaking protocols, and their insurers write contracts going forward.
What happened on April 18: the $292 million rsETH drain
At 17:35 UTC on April 18, 2026, an attacker minted 116,500 rsETH on Ethereum mainnet with no legitimate backing behind it. rsETH is Kelp DAO’s liquid restaking token, and the amount stolen represented roughly 18% of the token’s circulating supply, which stood at approximately 630,000 tokens at the time, according to DeFi research outlet DeFiPrime. At the market price that day, the haul was worth about $292 million, making it the largest single DeFi exploit reported in 2026.
The mechanism was not a smart contract bug in the traditional sense. Kelp’s rsETH bridge ran on LayerZero’s omnichain messaging protocol, and according to LayerZero’s own incident report, the attack chain started weeks earlier. LayerZero says a developer at the company was socially engineered starting March 6, 2026, which gave the attacker session keys into the company’s cloud and RPC infrastructure. From there, the attacker allegedly poisoned the memory of running RPC nodes so that internal monitoring tools saw normal traffic while the Decentralized Verifier Network, or DVN, received manipulated data. When an external RPC provider was knocked offline, the DVN’s signing service fell back on two compromised internal nodes, which then produced a valid-looking attestation for a forged cross-chain message.
That forged message hit a bridge configuration Kelp had built with a single verifier rather than a multi-party setup, so there was no second signer to catch the fraud. The message told Ethereum’s escrow contract to release 116,500 rsETH, and it did, without a matching deposit or burn on the other side. Security researchers at Mandiant and CrowdStrike, cited in LayerZero’s incident report, attributed the operation to TraderTraitor, also tracked as UNC4899, a group linked to North Korea’s Lazarus organization.
The fallout spread fast. Galaxy Research’s writeup on the incident described a cascade across nine DeFi protocols that depended on rsETH as collateral, and reported that Aave alone saw roughly $6.6 billion wiped from its total value locked as users scrambled to unwind positions tied to a token that had just lost a chunk of its backing. Some of that TVL loss reflects panic withdrawals rather than permanent impairment, but the speed of the contagion illustrates how tightly restaking tokens are woven into the rest of DeFi’s collateral base.
Kelp DAO’s lawsuit: what it actually alleges
The notice of civil claim, filed through Evercrest Technologies, names three causes of action: negligence, negligent misrepresentation, and defamation. The negligence and misrepresentation claims center on a specific allegation: Kelp says LayerZero reviewed and approved in writing the exact single-verifier bridge configuration that LayerZero later blamed for the loss. If that written approval exists and holds up as evidence, it turns the case from a dispute about whose code failed into a dispute about who signed off on the design before it failed.
Kelp DAO laid out its position directly in a public statement the same day it filed. “Today we filed a lawsuit against LayerZero and its co-founder, Bryan Pellegrino, to right the wrongs associated with the exploit of rsETH’s LayerZero bridge earlier this year,” Kelp DAO said in a post on X. The protocol went further in explaining its theory of the case: “As alleged in our lawsuit, the exploit was a direct result of LayerZero’s failures – including a failure to disclose weaknesses and risks inherent in LayerZero’s own technology, and a failure to prevent an infiltration of LayerZero’s own security infrastructure, which allowed attackers to exploit those weaknesses,” Kelp DAO wrote in the same thread on X.
Kelp DAO also used the statement to reassure users about the current state of the protocol, noting that remediation was already underway. “Since the exploit, we have taken action to ensure our users’ assets are secure, including by undertaking the migration of rsETH’s bridge to a more secure cross-chain security standard,” the protocol said, again via its official X account. That migration detail is notable on its own: five months after the exploit, Kelp is still in the process of moving off the single-verifier setup at the heart of the lawsuit, rather than having completed that work immediately after the hack.
The defamation claim is the wrinkle that separates this from a standard vendor-liability dispute. It targets statements Pellegrino reportedly made on Telegram and X in the aftermath of the hack, where he pinned the blame on Kelp’s configuration choices. By suing him personally rather than only the corporate entities, Kelp is betting that public statements made by a company co-founder in the heat of an incident can carry legal exposure separate from the underlying technical dispute.
LayerZero’s side: infrastructure compromise, not a design flaw
LayerZero’s own incident report, published as a PDF on the company’s site, does not dispute the core facts of the theft. It confirms the 116,500 rsETH figure, the $292 million valuation, and the attribution to TraderTraitor and Lazarus-linked infrastructure. Where the two sides diverge is on responsibility for the configuration that let the forged message through.
LayerZero’s account frames the failure primarily as a breach of its own cloud and RPC environment, caused by the social engineering of a staff member, and treats Kelp’s single-verifier deployment as a separate, compounding factor rather than something LayerZero is responsible for. That framing lines up with reporting cited in Kelp’s own claim: the lawsuit alleges LayerZero’s later public statements blaming Kelp’s configuration contradicted an earlier written approval of that same setup. Whether that written approval exists in the form Kelp describes, and what legal weight it carries, is now a question for the British Columbia court rather than for either party’s blog post.
It’s worth being precise about what remains unconfirmed. Neither company has published the full notice of civil claim or a formal legal response as of this writing, and there is no confirmed timeline for when LayerZero will file its defense. The available reporting also does not establish whether any of the 116,500 rsETH has been recovered, frozen, or laundered through mixers or exchanges since April, a gap that matters for calculating what, if any, restitution is realistic regardless of how the lawsuit resolves.
How the exploit technically worked, step by step
The technical chain behind the rsETH exploit is worth walking through in order, because it shows how a purely infrastructure-side compromise can produce a purely financial loss without a single line of Kelp’s own smart contract code being wrong.
- March 6, 2026: an attacker linked to TraderTraitor/UNC4899 reportedly began a social engineering campaign against a LayerZero Labs developer.
- The attacker obtained session keys and used them to move into LayerZero’s RPC cloud environment.
- Internal RPC nodes were compromised and patched in memory, so monitoring tools kept reporting normal behavior.
- An external RPC provider was disrupted, forcing LayerZero’s DVN signing service to depend solely on the two compromised internal nodes.
- Those nodes produced a valid attestation for a forged cross-chain message.
- Kelp’s rsETH bridge, configured with a single verifier rather than a multi-signer quorum, accepted the forged message without a second check.
- The Ethereum-side escrow released 116,500 rsETH with no corresponding deposit, burn, or backing asset.
Every individual link in that chain, the phishing, the RPC compromise, the single-verifier design, had to hold for the exploit to work. That’s part of why liability is contested: LayerZero can point to Kelp’s configuration choice as a but-for cause, while Kelp can point to LayerZero’s compromised infrastructure as the actual root cause that made the forged message possible in the first place.
2026’s DeFi exploit ledger: where the rsETH hack ranks
The rsETH exploit did not happen in isolation. 2026 has been a heavy year for large, infrastructure-level crypto losses, and comparing the rsETH incident against the rest of the field helps explain why Kelp chose to escalate to litigation rather than simply absorb the hit the way many hacked protocols have in prior years.
| Incident | Date | Amount lost | Root cause |
|---|---|---|---|
| Kelp DAO / rsETH (LayerZero bridge) | Apr. 18, 2026 | ~$292 million | Compromised verifier infrastructure + single-verifier config |
| Bitget exchange hot wallet | Sept. 24, 2026 | ~$351.6 million | Unauthorized transfers from hot/warm wallets |
| Liquid Network sidechain | Sept. 2026 | ~$320 million (85% later returned) | Sidechain security failure |
| Cosmos EVM module (6 chains) | Aug. 20-25, 2026 | Multiple chains drained | Critical balance-handling flaw, no CVE issued |
| Notional Finance escrow | Sept. 4, 2026 | ~$1.7 million | Escrow contract exploit |
| Payy Network Ethereum rollup | Sept. 24, 2026 | ~$1.8-1.9 million | Bridge/rollup contract drain |
What stands out is that the two largest 2026 incidents on this list, Kelp and Bitget, both involve centralized points of failure inside otherwise decentralized systems: a single verifier in Kelp’s case, and hot-wallet key management in Bitget’s. Neither was a case of an attacker finding an obscure bug in open, audited smart contract logic. That pattern supports Kelp’s argument that the industry’s real exposure right now sits in bridge and custody architecture, not in the contract layer that gets most of the audit attention.
Legal precedent: how this compares to Mango Markets, Euler, and Platypus
DeFi hack litigation has mostly followed one shape until now: chase the attacker. In the Mango Markets case, the legal and criminal focus fell on the individual accused of manipulating the protocol’s oracle pricing to drain funds. Euler Finance’s aftermath centered on negotiating directly with the exploiter for a return of funds, a path that produced one of the larger recoveries in DeFi history but never tested vendor liability in court. Platypus’s exploit likewise produced enforcement action aimed at the person accused of the unauthorized withdrawal, not at any third-party software provider.
Kelp’s claim against LayerZero breaks that pattern. Instead of asking a court to identify and punish the anonymous attacker, which is often practically impossible when the trail leads to North Korea-linked infrastructure, Kelp is asking a court to hold an identifiable, incorporated, Canada-registered infrastructure vendor and a named executive financially responsible for a loss that a third party actually carried out. That is a fundamentally different legal theory, closer to a professional negligence claim against an auditor or a cloud vendor than to a fraud claim against a hacker.
If Kelp succeeds, even partially, it would set an important marker for an industry that has largely operated on the assumption that infrastructure providers bear no downstream liability for how their tools get configured and deployed by client protocols. If Kelp fails, likely because of contractual disclaimers or limitation-of-liability clauses that are standard in crypto infrastructure agreements, that outcome would reinforce the current norm and push protocols back toward insurance and audits as their only real risk management tools.
Market impact: restaking tokens, LayerZero, and contagion risk
The April exploit’s second-order effects were arguably more damaging to the broader DeFi ecosystem than the direct $292 million loss. Because rsETH was used as collateral across multiple lending markets, the sudden uncertainty about its backing triggered de-risking across connected protocols. Galaxy Research’s estimate of roughly $6.6 billion in TVL pulled from Aave in the days following the hack illustrates how a single bridge failure in one restaking token can ripple through unrelated markets that merely accepted that token as collateral.
For LayerZero specifically, the reputational cost compounds an already crowded and competitive interoperability market, where Wormhole, Axelar, and Chainlink’s CCIP all compete for the same integration business from bridges and restaking protocols. A public lawsuit alleging that LayerZero approved, in writing, the exact configuration it later blamed for a $292 million loss is the kind of allegation that protocol teams evaluating cross-chain messaging vendors will factor into due diligence, regardless of how the case is ultimately resolved in court.
For Kelp DAO, the calculus cuts the other way. Filing a defamation claim alongside the negligence claims is a signal that reputational damage, not just the financial loss, is driving the litigation. A protocol that loses 18% of its token supply to a hack and then gets publicly blamed for the loss by its own infrastructure vendor has two problems to solve: recovering value and recovering credibility. The lawsuit is aimed at both.
Bridge security architecture: single-verifier vs. multi-verifier designs
The technical root of this dispute is a design choice that sounds simple but carries outsized risk: how many independent parties need to agree before a cross-chain message is accepted as valid. A single-verifier setup, the configuration Kelp used, means one signing party’s attestation is sufficient to move funds across chains. A multi-verifier setup requires independent agreement from more than one verification provider before a message clears, so a single compromised party cannot unilaterally forge a valid instruction.
| Configuration | How it works | Failure mode | Used by |
|---|---|---|---|
| Single-verifier (pre-exploit Kelp setup) | One DVN attests to message validity; bridge accepts on that basis alone | One compromised verifier can forge messages unilaterally | Kelp’s rsETH bridge before April 2026 |
| Multi-verifier / multi-DVN quorum | Two or more independent verifiers must agree before a message clears | Requires multiple parties compromised simultaneously; harder to forge | Kelp’s rsETH bridge after the post-exploit migration, per its own statement |
The core lesson security researchers have drawn from this incident, independent of how the lawsuit resolves, is that bridge configuration choices carry the same weight as smart contract code when it comes to security review. A protocol can pass every external audit of its own contracts and still be exposed if the messaging layer underneath it relies on a single point of trust. That is precisely the argument Kelp is making in court: that LayerZero, as the party that built and understood the messaging infrastructure, bore responsibility for flagging that risk before approving the deployment, not after a $292 million loss made it obvious.
What comes next in the British Columbia proceeding
Civil litigation in British Columbia follows a standard sequence: the notice of civil claim triggers a period for defendants to file a response, followed by discovery, where both sides exchange documents, including, potentially, the written bridge-configuration approval at the center of Kelp’s negligent misrepresentation claim. Cases of this size and complexity in Canadian courts commonly take one to three years to reach trial if they don’t settle first, and a large share of commercial disputes of this kind do settle before trial once discovery clarifies each side’s exposure.
The defamation claim against Pellegrino personally adds a wrinkle that could accelerate settlement pressure on LayerZero’s side, since individual executives are generally more motivated to resolve claims that name them personally than claims that only touch the corporate entity. At the same time, LayerZero has every incentive to fight the negligence and misrepresentation claims vigorously, since an adverse finding could expose the company to similar claims from other clients who deployed similar single-verifier configurations elsewhere in its ecosystem.
Predictions: where this case and the sector head next
- Expect other protocols that suffered bridge or messaging-layer exploits in 2026 to watch this case closely as a template, and potentially file similar vendor-liability claims of their own if Kelp’s theory survives an early motion to dismiss.
- Interoperability providers, including LayerZero’s direct competitors, will likely update client contracts to include more explicit disclaimers around configuration approval and liability caps, specifically to avoid the fact pattern Kelp is alleging.
- Expect increased due diligence demand from institutional restaking and lending protocols around whether their bridge dependencies use single-verifier or multi-verifier quorum designs, with multi-verifier becoming close to a baseline requirement for new integrations.
- The defamation claim against Pellegrino personally may push other executives at infrastructure firms to route incident commentary through legal or communications teams rather than personal social media accounts during future exploits.
- Regardless of the civil outcome, don’t expect a parallel SEC or criminal case tied directly to this lawsuit. The British Columbia claim is a private commercial dispute, and the attacker’s attribution to North Korea-linked TraderTraitor/UNC4899 puts any criminal accountability well outside the reach of a civil court judgment against LayerZero.
Why this case is a test for the entire interoperability industry
Cross-chain messaging has become foundational plumbing for DeFi, sitting underneath restaking tokens, wrapped assets, and liquidity that moves between a dozen or more chains. Yet the commercial relationships between protocols and messaging providers like LayerZero, Wormhole, Axelar, and Chainlink’s CCIP have rarely been tested against the question of who owns the downside when that plumbing fails. Audits typically cover a protocol’s own contracts. They rarely extend to a full security review of the third-party messaging layer a protocol depends on, largely because that layer is treated as someone else’s product to secure.
Kelp’s lawsuit forces a direct answer to that gap. If a court finds that LayerZero’s written approval of a bridge configuration created a duty of care, or that Pellegrino’s public statements crossed into defamation, it would put every interoperability vendor on notice that configuration sign-offs carry legal weight, not just technical weight. Conversely, a dismissal or a defense verdict would confirm what most infrastructure contracts already assume: that liability stops at the terms of service, and the protocol that chooses a configuration bears the risk of that choice, no matter who reviewed it beforehand.
Frequently asked questions
What is Kelp DAO and what is rsETH?
Kelp DAO is a liquid restaking protocol, and rsETH is the liquid restaking token it issues to represent staked and restaked ether. Holders can use rsETH across other DeFi protocols as collateral while still earning restaking rewards.
How much was stolen in the Kelp DAO exploit?
Attackers minted 116,500 rsETH without backing on April 18, 2026, worth approximately $292 million at the time, roughly 18% of the token’s circulating supply.
Who is being sued and where?
Evercrest Technologies, the entity behind Kelp DAO, sued LayerZero Labs Ltd., LayerZero Labs Canada Inc., and co-founder Bryan Pellegrino in the Supreme Court of British Columbia on September 25, 2026.
What legal claims does Kelp DAO make?
The claim includes negligence, negligent misrepresentation, and defamation, seeking damages, aggravated damages, and punitive damages.
Who is blamed for carrying out the exploit?
LayerZero’s incident report, citing analysis from Mandiant and CrowdStrike, attributes the attack to TraderTraitor, also tracked as UNC4899, a group linked to North Korea’s Lazarus organization.
Was it a smart contract bug?
No. The exploit stemmed from a compromise of LayerZero’s RPC and verifier infrastructure combined with Kelp’s single-verifier bridge configuration, not a flaw in Kelp’s own contract code.
Has Kelp DAO fixed the vulnerability?
Kelp says it has been migrating rsETH’s bridge to a more secure, multi-verifier cross-chain standard since the exploit, according to its own public statement.
How does this compare to past DeFi hack lawsuits?
Prior cases like Mango Markets, Euler Finance, and Platypus centered on pursuing the alleged attacker. Kelp’s case is unusual because it targets an infrastructure vendor and its executive for alleged negligence and misrepresentation rather than pursuing the attacker directly.




