KelpDAO has initiated legal proceedings against cross-chain protocol LayerZero and its co-founder and CEO, Bryan Pellegrino, following the theft of roughly $292 million from its rsETH bridge. The lawsuit alleges that LayerZero failed to disclose risks within its technology or prevent attackers from compromising its infrastructure. KelpDAO further claims that LayerZero had reviewed and endorsed its deployment and configuration in writing prior to the incident. In response, Pellegrino characterized the allegations as meritless and stated his intention to defend the case in Vancouver.
The dispute centers on an attack that occurred on April 18, which resulted in the theft of 116,500 rsETH. LayerZero’s final incident report indicated that attackers compromised internal nodes, causing the verifier to approve a forged cross-chain message. The protocol argued that the loss was possible because Kelp’s bridge relied on a single LayerZero decentralized verifier network (DVN) as its only verification path, noting it had recommended using multiple DVNs. Conversely, KelpDAO disputed this account, stating that its configuration had been discussed with LayerZero and confirmed as secure. Following the exploit, Kelp announced plans to migrate the rsETH bridge to Chainlink’s Cross-Chain Interoperability Protocol.
This litigation highlights the growing tension between DeFi protocols and their underlying infrastructure providers regarding liability for security breaches. By suing both the entity and its CEO, KelpDAO is challenging the traditional boundaries of responsibility in cross-chain interoperability, specifically questioning whether written endorsements of configurations constitute binding assurances of security. The case forces a critical examination of how risk disclosure obligations are met when complex technical dependencies, such as single verifier networks, are involved in high-value asset transfers.
From a market structure perspective, the outcome could significantly influence institutional adoption of cross-chain bridges by clarifying accountability frameworks. If courts determine that infrastructure providers bear partial responsibility for client-side configuration choices they have reviewed, it may lead to stricter compliance requirements and more conservative operational standards across the sector. Conversely, a ruling favoring LayerZero might reinforce the current model where end-users assume full responsibility for integration risks, potentially accelerating the migration toward protocols offering more robust, multi-layered verification guarantees like Chainlink.


