KelpDAO has escalated a months-long dispute with cross-chain protocol LayerZero into a formal legal battle, filing a civil lawsuit in British Columbia, Canada, against the company and its co-founder and CEO Bryan Pellegrino over the largest DeFi exploit of 2026 [1][2].
What Happened in April
The attack — attributed by some reports to a North Korean hacking group — struck KelpDAO's LayerZero-powered rsETH bridge on or around April 18–22, 2026, draining 116,500 rsETH worth approximately $292 million at the time [1][2]. The stolen tokens represented nearly a fifth of rsETH's entire circulating supply [2].
The exploit's aftershocks spread well beyond KelpDAO itself. Aave, the largest decentralized lending protocol, was forced to borrow $300 million to meet surging user withdrawal demands in the days that followed [2]. Within a week, the incident had erased an estimated $20 billion in total value locked (TVL) across DeFi markets — a scale of damage that drew commentary from analysts at JPMorgan about the structural vulnerabilities still embedded in decentralized finance [2].
How the Attack Worked — and Why Blame Is Contested
At the technical center of the dispute is LayerZero's decentralized verifier network (DVN) system, which cross-chain bridges use to authenticate messages between blockchains. LayerZero's own post-incident report concluded that attackers compromised its internal nodes, causing its verifier to approve a forged cross-chain message [1]. Because KelpDAO's bridge relied on a single LayerZero DVN as its only verification path — with no second independent verifier required — the bridge released the rsETH funds once that forged message was approved [1].
LayerZero argued that it had recommended using multiple DVNs and subsequently stopped serving as the sole required verifier for applications on its network [1]. In other words, the company's position is that KelpDAO's configuration choices amplified the damage.
KelpDAO flatly rejects that framing. In May, the protocol stated that its DVN configuration had been "confirmed as secure" in prior discussions with LayerZero, and accused the company of failing to adequately warn it about the risks involved [1]. The new lawsuit doubles down on that position, alleging that LayerZero not only failed to disclose weaknesses in its own technology but had also reviewed and endorsed KelpDAO's deployment and configuration in writing before the exploit occurred [1].
The Legal Claims
Filed as a notice of civil claim in British Columbia, the lawsuit names both LayerZero as a company and Pellegrino personally [2]. KelpDAO's core allegations are threefold: that LayerZero failed to disclose risks inherent in its technology, that it failed to prevent attackers from compromising its security infrastructure, and that it had previously signed off on the very configuration it later blamed for enabling the loss [1].
"The exploit was a direct result of LayerZero's failures, including a failure to disclose weaknesses and risks inherent in LayerZero's own technology," KelpDAO said in a statement [2]. The protocol added that LayerZero and Pellegrino had spent months publicly deflecting responsibility: "Rather than take responsibility, over the last few months, LayerZero and Mr. Pellegrino publicly blamed us for their failures" [2].
KelpDAO framed the lawsuit as both a user-protection measure and a matter of public record. "Our number one priority has always been and will remain the security of our users' assets," the protocol wrote. "But we also need to correct the record, and hold LayerZero and Mr. Pellegrino accountable for the harm they have caused us and the broader DeFi ecosystem" [1].
Pellegrino Pushes Back
Pellegrino moved quickly to dismiss the suit. Confirming the filing on social media, he described the claim as meritless and signaled he intends to fight it on home turf. "The claim continues to be meritless. I will meet them in Vancouver and defend myself accordingly," Pellegrino said [2]. Cointelegraph reported that LayerZero did not respond to a request for further comment before publication [1].
KelpDAO's Next Steps
Separate from the litigation, KelpDAO has already begun restructuring its cross-chain infrastructure. Following the exploit, the protocol announced plans to migrate the rsETH bridge away from LayerZero entirely, moving to Chainlink's Cross-Chain Interoperability Protocol (CCIP) as what it described as a more secure standard [1][2].
What to Watch
The case will play out in a British Columbia court, making it one of the more prominent DeFi-related lawsuits to land in a Canadian jurisdiction. Several key questions remain unresolved: whether LayerZero's written pre-exploit endorsement of KelpDAO's configuration proves legally significant; how courts will apportion liability between an infrastructure provider and a protocol that builds on top of it; and whether the outcome sets a precedent for how cross-chain bridge security responsibilities are defined across the industry. With $292 million in losses and a $20 billion market ripple as the backdrop, the stakes for both parties — and for DeFi infrastructure accountability more broadly — are substantial.
