Key points

  • KelpDAO says it filed a British Columbia civil claim against LayerZero and co-founder Bryan Pellegrino over the April rsETH bridge exploit.
  • The claim alleges LayerZero failed to disclose risks and prevent infiltration of infrastructure used to verify cross-chain messages.
  • Pellegrino called the claim meritless and said he and LayerZero would defend it in Vancouver; no court has ruled on the allegations.

KelpDAO has filed a civil claim in British Columbia against LayerZero and its co-founder Bryan Pellegrino, alleging failures connected to the April exploit that released about $292 million of rsETH from a cross-chain bridge. The filing turns a long-running dispute over security responsibility into a court case, but the allegations have not been tested and no court has found either defendant liable.

What KelpDAO alleges

In a statement published on September 25, KelpDAO said LayerZero failed to disclose weaknesses and risks in its technology and failed to prevent attackers from infiltrating infrastructure that supported the bridge. KelpDAO also alleged that LayerZero had reviewed and endorsed the deployment and configuration in writing. Those assertions are KelpDAO's account of the relationship and the incident, not established findings.

Related reporting: Symbiosis recovers 15 BTC after Bitcoin bridge exploit

KelpDAO said it brought the action to seek accountability for losses associated with the exploit. The project also said it has since migrated rsETH bridging to a different cross-chain security standard. Its statement did not specify a damages figure beyond linking the claim to the roughly $292 million incident.

LayerZero rejects the claim

Pellegrino responded on X that Evercrest, the entity behind KelpDAO, had filed a notice of civil claim against him and LayerZero in British Columbia. He called the claim meritless and said he would defend it in Vancouver. LayerZero's response means the central questions about disclosures, configuration advice and operational responsibility remain contested.

How the bridge exploit unfolded

Chainalysis reported that the April 18 attack compromised two internal remote procedure call nodes and disrupted an external node with a distributed denial-of-service attack. The poisoned nodes then showed a burn of rsETH on the source chain that had not occurred. A LayerZero Labs decentralized verifier network operating in a one-of-one configuration accepted that false view, and the Ethereum-side bridge adapter released 116,500 rsETH.

The attack did not rely on a conventional smart-contract flaw. Instead, it targeted off-chain infrastructure used to tell the verifier what happened on another chain. That distinction matters because cross-chain applications can execute valid on-chain transactions based on corrupted external data. KelpDAO and LayerZero have previously disputed who was responsible for the single-verifier configuration and what safeguards had been recommended.

Recovery reduced but did not erase the damage

KelpDAO paused affected contracts quickly enough to block a follow-up attempt involving another 40,000 rsETH, valued at roughly $95 million at the time. The Arbitrum Security Council later froze 30,766 ETH connected to the attacker. Those interventions limited further movement, but Chainalysis noted that the freeze did not by itself restore the missing backing created when rsETH was released without a corresponding burn.

What comes next

The litigation could force a more detailed examination of bridge deployment decisions, security representations and the division of responsibility between an application and its messaging provider. If the case proceeds into evidence gathering, written communications and technical records may clarify what each party recommended, operated and understood before the exploit. The next milestones will depend on the defendants' formal response and the British Columbia court process. Until pleadings and evidence are tested, claims from both sides should be treated as positions in an active dispute rather than conclusions about fault.

Sources

AI-generated editorial image; not a photograph of the reported event. Prepared with AI assistance and source verification.