Gavel, pen and lawsuit filing form on a desk, illustrating civil legal action and court proceedings.
BUSINESS

KelpDAO Sues LayerZero Over $292M Exploit

Image credit: Shutterstock

KelpDAO has sued LayerZero Labs and co-founder and CEO Bryan Pellegrino over the April exploit that drained 116,500 rsETH, worth about $292 million at the time.

Evercrest Technologies, the legal entity behind Kelp, filed the civil claim in British Columbia on Sept. 24. Kelp alleges LayerZero failed to disclose risks in its technology and protect infrastructure later compromised by attackers. No court has ruled on those allegations.

Kelp Says LayerZero Approved 1-Of-1 Verifier Setup

The dispute centers on the LayerZero Decentralized Verifier Network used by Kelp’s rsETH bridge.

At the time of the attack, the bridge used a 1-of-1 configuration with LayerZero Labs as its sole required verifier. Kelp says LayerZero reviewed and approved that deployment in writing before the exploit, challenging claims that Kelp independently created the security weakness.

LayerZero has maintained that applications control their own verifier configurations and that using a single DVN removed the redundancy that could have stopped a forged cross-chain message. Pellegrino has called Kelp’s lawsuit meritless and said he will defend himself and LayerZero in Vancouver.

Compromised LayerZero Infrastructure Produced Valid Attestation 

LayerZero’s final incident report found that the attack began after a developer was socially engineered in March. The attacker obtained session keys, entered LayerZero’s RPC cloud environment and poisoned internal nodes used by its DVN.

A denial-of-service attack against an external RPC provider then left the verifier relying on compromised internal nodes. The system produced a valid attestation for a forged cross-chain message, allowing the bridge to release 116,500 rsETH without a corresponding legitimate transaction on the source chain.

LayerZero later stopped allowing its own DVN to operate as the sole required verifier and rebuilt the compromised infrastructure.

Kelp Moved rsETH Bridging to Chainlink After April Attack

Kelp responded by migrating rsETH bridging from LayerZero’s OFT framework to Chainlink CCIP and strengthening verification while recovery work continued.

By May 25, Kelp had completed the operational portion of its rsETH recovery plan after refilling the affected bridge adapter.

The new lawsuit shifts the remaining dispute from competing postmortems to a court proceeding over responsibility for the compromised infrastructure, the single-verifier setup and the losses created by the April attack.

More For You

Explore More News