Press Enter to search · ESC to close

DeFi

Kelp DAO Sues LayerZero Over $292M rsETH Bridge Exploit

Kelp DAO is suing LayerZero and CEO Bryan Pellegrino over a $292 million rsETH bridge exploit, alleging the protocol approved the single-verifier setup attackers used and then blamed Kelp. Pellegrino calls the claim meritless. The case could set precedent for liability in cross-chain infrastructure.

Kelp DAO Takes LayerZero to Court Over $292 Million rsETH Exploit

Kelp DAO, the developer behind the rsETH liquid restaking token, has filed a lawsuit against interoperability protocol LayerZero and its CEO Bryan Pellegrino, seeking accountability for a $292 million bridge exploit that drained funds in April. At the heart of the dispute is a single-verifier configuration that Kelp claims LayerZero approved — and then publicly blamed Kelp for adopting. Pellegrino has dismissed the suit as meritless.

The Core Allegation: Who Owned the Risk?

The lawsuit centers on a familiar tension in cross-chain security: the trade-off between cost, speed, and decentralization. Kelp alleges that LayerZero signed off on a bridge setup secured by only one verifier, a design that collapses the security model of a multi-verifier bridge into a single point of failure. When attackers exploited that weakness, Kelp argues, LayerZero shifted responsibility to its integration partner rather than owning the architecture it endorsed.

LayerZero’s position is that integrators are responsible for their own security configurations. Pellegrino’s rebuttal — that the claim is meritless — signals the protocol intends to fight rather than settle, setting up a legal battle that could define liability boundaries across the interoperability stack.

Why This Matters for Restaking and Bridge Security

Liquid restaking tokens like rsETH sit at the intersection of two of DeFi’s most sensitive risk surfaces: restaking, where slashing and operator behavior can cascade, and bridges, which remain the single largest source of catastrophic losses in crypto. The exploit underscores a structural problem:

  • Verifier concentration: A one-verifier bridge is functionally a trusted custodian, not a trust-minimized system.
  • Accountability gaps: When infrastructure providers and integrators disagree on who approved what, users bear the loss.
  • Composability contagion: rsETH is woven into lending markets and yield strategies, so a bridge failure ripples far beyond a single protocol.

Legal Precedent in the Making

This case could become a reference point for how courts treat shared responsibility in modular blockchain infrastructure. If Kelp prevails, infrastructure providers may face pressure to audit and restrict risky configurations — or to explicitly disclaim them in writing. If LayerZero prevails, integrators could be left holding the bag for security choices made under provider guidance.

Forward-Looking Perspective

Regardless of the verdict, the market is already pricing in the lesson: multi-verifier designs, formal configuration attestations, and on-chain parameter disclosure are moving from best practice to baseline expectation. For restaking protocols, the incident is a reminder that composability amplifies both yield and tail risk. Expect insurers, auditors, and governance forums to harden standards — and expect this lawsuit to shape the contractual language of every bridge integration that follows.

View original

Share
Risk notice This site provides news and information on the crypto, blockchain and Web3 industry for reference only and does not constitute investment advice or any promise of returns. Virtual currency-related activities are illegal financial activities in mainland China; digital asset prices are highly volatile; use at your own risk. This site does not provide trading, token issuance or related referral services.

Related Reading

Latest News

TREE NEWS share card
Long-press image above → Save to Photos / Share
Pitch us Feedback