Kelp DAO Sues LayerZero After $292 Million rsETH Hack
Kelp says LayerZero had approved the bridge setup, while the attack ran through a 1-of-1 verifier. The case puts cross-chain security and liability in DeFi in the spotlight.

Key Takeaways
- Kelp DAO has sued LayerZero and co-founder Bryan Pellegrino after the hack that stole about $292 million in rsETH in April.
- According to Kelp, LayerZero hid flaws in its technology and did too little to stop the attack through the bridge.
- The case centers on a 1-of-1 bridge configuration and could have consequences for liability across the broader DeFi sector.
Kelp DAO has sued LayerZero and co-founder Bryan Pellegrino after the hack in which about $292 million (€257 million) in rsETH was stolen in April. The restaking protocol says LayerZero hid flaws in its own technology and did not do enough to stop the attack.
How the Hack Unfolded
On April 18, attackers drained about 116,500 rsETH through Kelp DAO's LayerZero bridge. According to the complaint, that made it the biggest DeFi hack of 2026. LayerZero later linked the attack to the Lazarus subgroup TraderTraitor.
LayerZero said the attackers had taken over enough remote procedure call, or RPC, nodes to send fake data to the bridge's verifier. Those servers pass blockchain data to applications. As a result, the verifier approved an rsETH burn that never actually happened, after which the Ethereum contract released funds.
LayerZero instead pointed to Kelp's setup. The bridge worked with a single verifier from LayerZero Labs, a 1-of-1 configuration. That immediately widened the security debate around cross-chain infrastructure beyond just this one attack.
Kelp Pushes Back
Kelp now says LayerZero and Pellegrino spent months publicly blaming the protocol. According to Kelp, LayerZero had actually reviewed and approved the rollout and configuration in writing. The protocol has published the complaint itself and wants LayerZero and Pellegrino held liable for damage to Kelp and the broader DeFi sector.
Since the hack, Kelp says it has been working on a safer way to move rsETH across chains. Earlier, the protocol had already named Chainlink CCIP as a replacement, an alternative cross-chain messaging system. In May, a U.S. judge also blocked Arbitrum DAO from moving 30,766 ETH that it had frozen from the hacker.
The fallout from the attack was also felt elsewhere in DeFi: Aave was still missing billions in deposits after the Kelp hack, because the exploit also caused damage there through unbacked rsETH.
Why This Matters More Broadly
The case could matter for European crypto readers because cross-chain bridges are a standard part of DeFi, but also a recurring security risk. The complaint shows that not only the protocols themselves, but also the parties behind the infrastructure, can come under legal pressure if an exploit runs through their systems. That makes the outcome interesting for projects that depend on the same kind of bridge setup.