KelpDAO has sued LayerZero and its co-founder, Bryan Pellegrino, alleging undisclosed weaknesses in LayerZero’s cross-chain protocol enabled the $292 million exploit. The April 22 attack drained 116,500 rsETH and was described as the largest exploit of 2026 so far.
Why it matters
KelpDAO alleges LayerZero failed to disclose risks in its technology and failed to prevent the attackers from infiltrating its security infrastructure. The protocol says it is bringing the claim to hold LayerZero and Pellegrino accountable for harm to KelpDAO and the wider DeFi ecosystem. Pellegrino called the lawsuit meritless and said he would defend himself and LayerZero in a British Columbia court.
The exploit’s effects spread beyond KelpDAO. Aave, the largest DeFi lending pool, borrowed $300 million to meet rising withdrawal demand, while the incident contributed to a broader liquidity crisis that erased $20 billion in DeFi deposits. The attack was attributed to a North Korean hacking group, though the lawsuit centers on the alleged security failures and disclosure obligations.
Market impact
KelpDAO says it has moved rsETH’s bridge to a more secure cross-chain security standard to protect user assets. The legal dispute now puts the competing accounts of the exploit before a court, while the withdrawal shock highlights how bridge failures can transmit stress across DeFi lending and liquidity markets.
Investors will be watching the case and any further security measures across cross-chain protocols. The dispute does not itself resolve the technical or legal questions, but it raises the stakes for how bridge risks are disclosed and who bears responsibility when an exploit spreads through DeFi.
Frequently asked questions
-
What does KelpDAO allege LayerZero did wrong?
KelpDAO alleges LayerZero failed to disclose weaknesses and risks in its cross-chain technology and failed to prevent infiltration of its security infrastructure.
-
How much rsETH did the April 22 attack drain?
The attack drained 116,500 rsETH, valued at about $292 million in the seed report.
-
How did the exploit affect Aave?
Aave borrowed $300 million to meet increasing user demand for withdrawals after the attack.
-
What broader DeFi impact followed the exploit?
The exploit contributed to a liquidity crisis that erased $20 billion in DeFi deposits.
-
What security step has KelpDAO taken since the attack?
KelpDAO says it migrated rsETH’s bridge to a more secure cross-chain security standard to protect user assets.
CoinDesk