KelpDAO Sues LayerZero Over $292M rsETH Exploit and Bridge Security

KelpDAO rsETH exploit and LayerZero bridge security lawsuit illustration with Ethereum, crypto tokens, broken bridge, and legal gavel.

KelpDAO operator Evercrest Technologies has sued LayerZero Labs and CEO Bryan Pellegrino in British Columbia over an April exploit that drained 116,500 rsETH worth about $292 million.

Evercrest filed the civil claim on September 24, taking the dispute over the attack into court. KelpDAO says LayerZero reviewed and approved its bridge configuration before the exploit. LayerZero, however, has argued that KelpDAO’s decision to use a single verifier left the bridge vulnerable to a critical failure.

Pellegrino disclosed the lawsuit on X and called the claim “meritless.” He said he plans to defend himself and LayerZero in Vancouver.

https://x.com/PrimordialAA/status/2103257436048310471?s=20 

The competing accounts center on how LayerZero’s verification infrastructure was configured and what happened after an attacker gained access to it.

What Happened to the rsETH Bridge

The exploit took place on April 18 after an attacker submitted a forged LayerZero message claiming that rsETH had been burned on another chain.

At the time, the bridge used a 1-of-1 Decentralized Verifier Network, or DVN, configuration. That meant a single verifier could approve a cross-chain message.

LayerZero said an attacker compromised infrastructure used by its DVN after socially engineering one of its developers and obtaining session credentials. The attacker then gained access to internal RPC infrastructure and manipulated information supplied to the verifier.

An external RPC provider was also disrupted during the attack. LayerZero said the DVN subsequently relied on the compromised infrastructure and signed a forged cross-chain message.

KelpDAO’s Ethereum-side bridge accepted the message and released 116,500 rsETH to an address controlled by the attacker. The rsETH smart contract itself was not exploited, according to security researchers. Instead, the attack targeted the infrastructure responsible for verifying the cross-chain message.

LayerZero attributed the attack to TraderTraitor, also known as UNC4899. Security researchers have linked the group to North Korea.

A second transaction later targeted another 40,000 rsETH, then worth roughly $95 million. KelpDAO paused the affected contracts before that transfer could be completed.

Single Verifier Becomes Key Dispute

The 1-of-1 configuration has since become a central point of disagreement between KelpDAO and LayerZero.

LayerZero said using one verifier created a single point of failure. The company said it had recommended using multiple independent DVNs, which could have prevented one compromised verifier from approving the forged message.

KelpDAO disputes that explanation. The protocol says LayerZero had reviewed the bridge deployment and configuration and endorsed it in writing.

Pellegrino has also argued that KelpDAO changed its verifier configuration. He has pointed to LayerZero documentation that recommends multiple verifiers for stronger security.

KelpDAO’s lawsuit alleges that LayerZero failed to disclose risks associated with its technology and did not adequately secure infrastructure used by its verifier. It also claims LayerZero later placed responsibility on KelpDAO despite having reviewed the deployment.

Those allegations have not been tested in court. LayerZero and Pellegrino dispute KelpDAO’s account.

LayerZero Later Changed Its Approach

LayerZero subsequently acknowledged that allowing its DVN to act as the sole verifier for high-value transactions was a security mistake.

The company said it would no longer allow its DVN to serve as the only verifier in such configurations. It also introduced stronger verification requirements after the incident.

At the same time, LayerZero continued to point to the single-verifier setup as an important factor in the loss. Its incident report said applications using multiple independent DVNs could have rejected a forged message if one verifier had been compromised.

KelpDAO later moved rsETH cross-chain transfers away from LayerZero and toward Chainlink’s Cross-Chain Interoperability Protocol.

The exploit also spread into DeFi lending markets after the attacker used the stolen rsETH as collateral. Aave was among the protocols affected as the value and backing of rsETH came under pressure.

Recovery Efforts Followed the Exploit

The incident prompted a recovery effort involving KelpDAO, Aave and other DeFi participants.

The stolen rsETH had entered lending markets as collateral, creating additional risks beyond the initial bridge loss. Efforts were subsequently made to restore the backing of affected rsETH and address the resulting market pressure.

The recovery eventually restored the backing required for affected markets. KelpDAO also continued shifting its cross-chain infrastructure away from LayerZero.

The exploit highlighted the risks that can arise when cross-chain applications rely on a single verification service, particularly when large amounts of assets can be released based on a verified message.

Evercrest Takes the Dispute to Court

Evercrest’s lawsuit now puts the competing accounts over the exploit before a British Columbia court.

KelpDAO maintains that LayerZero’s infrastructure was compromised and that the company had reviewed its bridge configuration beforehand. LayerZero has maintained that KelpDAO’s 1-of-1 verifier setup allowed the infrastructure breach to result in the loss of rsETH.

The court will have to consider the parties’ claims and defenses, including the bridge configuration, LayerZero’s infrastructure and the events surrounding the exploit.

For now, Evercrest’s allegations remain unproven. Pellegrino has said he intends to contest the claim in Vancouver.

Farhana Khan

Farhana Khan is a crypto and blockchain journalist with 4+ years of experience covering Bitcoin, Ethereum, DeFi, and global crypto regulation. she focuses on market trends, on -chain data, and institutional adoption.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top