What happens when a liquid staking token worth hundreds of millions leaves a protocol through a bridge that both sides later describe in completely different ways? That is the uncomfortable question hanging over DeFi this week. KelpDAO has taken LayerZero and co-founder Bryan Pellegrino to court in British Columbia after the April 18 incident that drained 116,500 rsETH, a haul valued at about $292 million at the time. I have covered more than a few post-hack blame games, and this one feels different. It is not only a technical post-mortem. It is a fight over paperwork, defaults, and who was supposed to notice a single point of failure before an attacker walked through it.
Why This Lawsuit Matters Far Beyond One Token
On September 24, Evercrest Technologies Inc., the legal entity behind Kelp, filed the action. Kelp’s current terms name that company as the firm providing the Kelp application. The public statement that followed was blunt. The protocol wants a court to examine what it calls failures tied to LayerZero infrastructure. No judge has ruled on anything yet. That part needs to stay in view, because social media will treat allegations as verdicts by lunchtime.
Pellegrino called the claims meritless and said he will defend himself and LayerZero in Vancouver. The civil claim names both the company and Pellegrino personally. In my experience, naming a founder individually raises the temperature immediately. It also raises the legal bar. Courts do not hand out personal liability because a protocol tweeted a harsh thread.
The core of the story is simple enough to say and messy to prove. Attackers used a compromised verification path to convince Kelp’s Ethereum bridge that a burn had happened on the source chain when it had not. Funds left. Users panicked. Then both teams spent months arguing about configuration. Now a Canadian court gets the file.
What Actually Left The Protocol On April 18
The first successful drain moved 116,500 rsETH. Market value at the time sat near $292 million. A second attempt targeted another 40,000 rsETH, then worth roughly $95 million to $100 million. That second packet did not land. Kelp paused contracts about 46 minutes after the first drain. Those 46 minutes will show up in every timeline exhibit, because they sit right on the line between containment and catastrophe.
Investigators later described the event as an attack on off-chain verification infrastructure, not a bug inside the rsETH token contract itself. That distinction matters for holders who still ask whether the token logic was rotten. The contract did what a bridge adapter is designed to do when a verifier says a message is valid. The fight is about how that message became valid.
The stolen amount was large enough to stress lending markets that had accepted the token as collateral, which is why recovery work spilled beyond one protocol’s dashboard.
Stolen rsETH did not sit politely in one wallet. It moved into collateral loops. Other DeFi platforms had to coordinate because the theft created losses in lending markets. Kelp later committed 2,000 ETH to a recovery effort. That is not a rounding error, and it is also not a full make-whole. Anyone who has watched a large exploit knows the difference.
The Configuration Dispute That Now Sits In A Complaint
LayerZero’s April account said Kelp used a 1-of-1 Decentralized Verifier Network, often shortened to DVN. In plain English, one verifier path could approve a cross-chain message. There was no second independent verifier standing in the way of a forged packet. LayerZero said it had recommended diversification and framed the setup as a single point of failure.
Kelp tells a different story. The protocol says LayerZero reviewed and approved the deployment and configuration in writing before April. That claim, if the documents exist and say what Kelp thinks they say, is the spine of the lawsuit. Written approval is not a vibe. It is an exhibit.
LayerZero has maintained that Kelp manually moved to the 1-of-1 setup. Pellegrino later said Kelp originally used multi-DVN or DeadDVN defaults before changing the rsETH deployment. Kelp disputes that description of the talks. Perhaps the most interesting aspect is how both sides now treat “default” as a moral word. In software, a default is often just the path of least resistance. In court, it can look like an instruction.
- Kelp says the bridge followed documented defaults and relied on LayerZero-operated infrastructure.
- LayerZero says a hardened multi-verifier design would have blocked one compromised signer.
- Both sides agree attackers abused verification, not a hidden mint function in the token itself.
I have found that these arguments rarely stay technical for long. They slide into questions of duty. Did a vendor owe a warning in bold letters? Did an integrator owe a second verifier even if the first path looked official? Courts like paper trails more than Discord lore.
How The Intrusion Reached LayerZero Infrastructure
LayerZero’s later incident report said the intrusion began on March 6. An attacker socially engineered a developer and obtained session credentials. From there the attacker entered an RPC cloud environment and altered internal RPC nodes used by the LayerZero Labs DVN. That is not a smart-contract reentrancy tale. It is an access-control tale with a crypto ending.
On April 18, the compromised nodes supplied false chain data. Attackers also launched a denial-of-service campaign against external RPC providers. The effect was ugly and rather elegant in a grim way. The DVN’s available picture of the world said the forged message looked valid, so the DVN signed it. Kelp’s Ethereum bridge then released rsETH.
Security firms looking at the same facts landed in nearby places. One analysis stressed that a sole DVN authenticated the false message and that the missing second verifier let the packet reach Kelp’s adapter. Another focused on manipulated RPC nodes and the forced reliance on those nodes after outside providers were disrupted. You can argue about labels. You cannot argue that two failures stacked.
Failure stack in short form: Compromised operator environment Distorted RPC view of source-chain state Single verifier path willing to sign Bridge adapter that trusted the signed packet
LayerZero and several researchers attributed the campaign to a North Korea-linked cluster associated with a well-known state-backed theft group. That attribution comes from the company’s investigation and associated security work. It does not decide who pays whom in British Columbia. Attribution answers “who kicked the door.” The lawsuit asks “who left the latch like that.”
What Kelp Alleges And What LayerZero Denies
Kelp’s public framing is that LayerZero failed to disclose weaknesses and risks in its technology and failed to stop attackers from penetrating security infrastructure used by its verifier. Those are allegations. I will keep repeating that word because lawsuits invite readers to skip it.
LayerZero’s defense, at least in public, keeps returning to design choice. If Kelp had required multiple independent DVNs to agree, one compromised verifier would not have been enough. The May report said a hardened configuration would have stopped the forged message from authorizing the release. That is a strong counter if a court treats integrator configuration as the decisive act.
Kelp’s counter is equally sharp. Months of public comments, in Kelp’s view, tried to park responsibility on the victim protocol after infrastructure controlled by LayerZero had already been breached. If you have ever watched two companies draft incident posts in real time, you know how quickly “shared responsibility” becomes “your dashboard, your problem.”
A court can accept that an attacker was sophisticated and still ask whether a vendor’s own environment was the weak joint in the pipe.
There is a human texture here that dry incident reports miss. Teams who just lost user funds do not enjoy being told they picked the unsafe preset. Teams who just got socially engineered do not enjoy being told their product is the villain. Both reactions are understandable. Neither one is evidence.
Why British Columbia And Why A Personal Defendant
Filing in British Columbia is not a random dart throw if the corporate footprint supports it. Under the province’s Supreme Court Civil Rules, a defendant generally has 21 days to respond after service in Canada, 35 days after service in the United States, or 49 days when served elsewhere, unless a judge sets another clock. Pellegrino has already said he intends to contest the action in Vancouver. That is a signal of venue acceptance, not of settlement.
Why name a co-founder? Plaintiffs sometimes do it when they want discovery from a person who spoke in public, signed communications, or directed a security response. Defendants sometimes call that move theatrical. A court will look at control, duty, and whether personal conduct is even in play. I would not bet the house on personal liability just because a complaint includes a famous name. I also would not ignore the discovery pressure that follows.
Legal process is slower than Crypto Twitter, which is a mercy. The first useful documents will not be memes. They will be emails, configuration screenshots, review tickets, and the exact language of any written approval Kelp says exists.
The Migration Away From The Old Bridge Path
While recovery work continued, Kelp started changing how rsETH moves across chains. In May it announced a shift of cross-chain transfers away from LayerZero’s OFT framework toward another interoperability network. That migration happened while the two teams were still arguing about the original setup. Timing like that is never socially neutral. It reads as both risk management and a press statement.
By May 25, Kelp said it had transferred the final 20,373.72 rsETH tranche needed for its operational recovery plan. Minting, redemptions, and rewards resumed. Bridging services reopened after asset transfers restored backing to the affected structure. If you held rsETH through that window, those dates were not trivia. They were the difference between a frozen product and a functioning one.
LayerZero, for its part, said it ended support for 1-of-1 DVN configurations and pushed affected applications toward multi-verifier setups. The updated model, as described by the company, wants more independent verification paths. That change is an implicit lesson even if the lawsuit later fails. Single-key thinking does not age well once an attacker has used it in public.
| Date | Event | Why it still matters |
| March 6 | Reported start of social-engineering intrusion | Shows the breach predates the drain |
| April 18 | 116,500 rsETH released on a forged message | Core loss event |
| April 18 | Second 40,000 rsETH attempt stopped after pause | Containment window of about 46 minutes |
| May | Detailed incident report and bridge migration plans | Public record of competing narratives |
| September 24 | Civil claim filed in British Columbia | Dispute leaves blogs and enters court |
Recovery Was A Market Problem, Not A Press Release
When a liquid staking token is used as collateral, a theft does not stay inside one protocol’s treasury story. Lending pools mark risk. Liquidations threaten to fire. Other teams get dragged into war rooms they did not schedule. That is what happened after April 18. Aave and other participants joined a recovery process because stolen rsETH had been posted against loans.
Kelp’s 2,000 ETH commitment was part of that process. It will not satisfy every critic. It also should not be memory-holed. Protocols that vanish after a drain teach a worse lesson than protocols that argue in public and still move funds back toward solvency.
There is a separate, quieter story about users who bridged in good faith and then watched social feeds fill with forensic threads. Those users did not choose a 1-of-1 DVN in a settings panel. They chose a yield product. The industry still talks as if every holder is a protocol engineer. That habit is getting expensive.
The Security Lesson People Keep Softening
Cross-chain systems fail in layers. A contract can be clean and still release funds if the message layer lies. A verifier can be honest and still sign if its data diet is poisoned. An integrator can follow a vendor workflow and still inherit the vendor’s operational risk. I keep seeing teams treat those layers as optional footnotes. They are the product.
- Assume any single verifier can be socially engineered or fed bad RPC data.
- Require independent agreement before a bridge adapter unlocks value.
- Treat operator cloud access with the same paranoia usually reserved for admin keys.
- Write down who approved a configuration, and keep that record boring and complete.
- Plan a pause path that does not depend on one tired person noticing a Telegram ping.
None of that is exotic. It is just unfashionable while deposits are climbing. After a nine-figure event, it suddenly sounds like wisdom. Funny how that works.
LayerZero’s later move away from 1-of-1 support is the kind of product change that should have been a default sermon years earlier. Kelp’s later move to a different interoperability stack is the kind of vendor change that usually happens only after trust is already cracked. Both moves can be rational. Both can also be read as exhibits.
What A Court Can Actually Decide
A civil court will not redesign DeFi. It can decide whether representations were misleading, whether a duty of care existed, whether warnings were adequate, and whether losses flow from a defendant’s conduct rather than from a plaintiff’s own configuration choices. Those are dry sentences with sharp teeth.
Kelp says written records show LayerZero reviewed the setup. LayerZero says the dangerous part was Kelp’s verifier count. If both things are partly true, the case becomes a comparative-fault story. Crypto culture hates that phrase. Insurance lawyers live on it.
Do not expect a Hollywood ending in 21 days. Expect motions, sealed annexes, and a long argument about what “approved” meant in an email that nobody thought would be read aloud in Vancouver. That is how these files age.
The Industry Habit Of Talking Past The Loss
After every major exploit, two choruses start. One chorus says the victim protocol was reckless. The other says the infrastructure vendor sold safety and delivered a fog machine. Sometimes both choruses are half right. The users in the middle still need a timeline, a recovery path, and an honest map of remaining risk.
I have found that the most useful questions are almost rude in their simplicity. Who could halt the bridge? Who could see malformed packets in time? Who owned the RPC path the verifier trusted? Who signed off on a one-verifier design in writing? If a team cannot answer those without a 40-page thread, the architecture is already telling on itself.
There is also a language problem. Words like decentralized verifier sound like a crowd. A 1-of-1 path is a crowd of one. Marketing will keep using the long phrase. Risk committees should keep counting the actual signatures required.
If only one party can reject a false cross-chain message, you do not have a network of skepticism. You have a polite handshake with extra branding.
What Holders And Builders Should Watch Next
Watch the response deadline more than the quote tweets. Watch whether Kelp files supporting documents that actually show prior written approval. Watch whether LayerZero argues that any review was general product guidance rather than a blessing of a 1-of-1 production bridge. Watch whether other protocols still running thin verifier sets quietly add a second path without a blog post.
Also watch lending markets that still accept bridged liquid staking tokens as if bridge risk were a rounding item. It is not. Collateral that can vanish through a message layer is a different animal from collateral that can only be minted by a conservative staking contract.
And keep the personal claim in perspective. A founder can be named and still win. A company can be right about configuration and still have failed at operational security. Those outcomes can coexist. The internet hates coexistence. Courts deal with it every week.
A Longer View On Trust After A $292 Million Hole
Liquid restaking and liquid staking derivatives grew because they promised familiar yield with portable tokens. Portability requires bridges. Bridges require someone, or several someones, to swear that a burn or lock on chain A matches a mint or release on chain B. That oath is the product. Everything else is wrapping paper.
When the oath is produced by a verifier that ate poisoned RPC data, users do not experience an elegant distributed systems paper. They experience a missing balance. Then they experience two teams explaining why the missing balance is mostly the other team’s philosophy of defaults.
I do not think this case will “kill” interoperability. Markets have a short memory for architecture and a long memory for unrecovered money. If recovery work continues and court filings stay specific, the sector will treat this as an expensive seminar. If the filings dissolve into vibes, the seminar gets wasted.
There is a personal note I cannot quite shake. The industry still sells “trustlessness” while running on session cookies, cloud roles, and a handful of people who can be phished on a Thursday. That gap is not a secret anymore. April 18 made it visible at a size that finance desks can price.
Practical Takeaways Without The Courtroom Theater
If you build a bridged asset, write the verifier policy like a liability memo, not like a launch checklist. If you integrate a messaging stack, assume the operator environment can be hit before your contracts ever look strange on a block explorer. If you hold a bridged receipt token, ask how many independent parties must agree before your coins can leave. If the answer is one, you are not conservative. You are optimistic.
- Demand multi-party verification for high-value releases.
- Separate vendor marketing language from production configuration.
- Keep written approval records even when everyone is friendly.
- Rehearse pause authority before the 46-minute clock starts.
- Treat social engineering of developers as a first-class bridge risk.
None of those points require you to pick a favorite company in this dispute. That is the point. Fans make poor risk officers.
Where The Story Stands This Morning
KelpDAO, through Evercrest Technologies Inc., has sued LayerZero and Bryan Pellegrino in British Columbia over the April rsETH bridge exploit. About 116,500 rsETH left through a forged cross-chain message after attackers compromised infrastructure tied to a verifier path. A second attempt failed after a pause. Recovery work moved assets, reopened product functions, and still left a bitter argument about who created the failure point.
LayerZero says a 1-of-1 verifier design was the hole that mattered. Kelp says the vendor reviewed the setup, ran critical infrastructure, and then spent months pointing elsewhere. Pellegrino says the lawsuit is meritless and he will fight it in Vancouver. Those are the live facts. The rest is commentary, including mine.
If you came here for a villain in a cape, you will leave hungry. If you came here to understand why a $292 million drain turned into a Canadian civil claim, the picture is clearer. A bridge trusted a signed message. The signer trusted a poisoned view of the chain. Two companies now want a court to decide whose trust was negligent. That is not a small question for one token. It is the bill coming due for an industry that connected chains faster than it connected accountability.