KelpDAO sues LayerZero over $292M rsETH exploit: court fight begins

Share

KelpDAO is taking the offensive against LayerZero in court, nine months after the exploit that drained 116,500 rsETH from the Unichain bridge and rattled the entire DeFi ecosystem. The complaint, filed by parent company Evercrest Technologies in Canada, places direct responsibility on the interoperability protocol for having endorsed an architecture that became the fatal flaw on April 18, 2026.

🔑 Key takeaways

  • $292M drained via the rsETH-Unichain bridge exploit using LayerZero’s 1-of-1 DVN configuration.
  • Evercrest seeks 2,000 ETH plus compensatory, aggravated and punitive damages against LayerZero Labs and Bryan Pellegrino.
  • Aave absorbed $8.45B in withdrawals over two days; bad debt estimated at $123.7M to $230.1M.
  • The Arbitrum Security Council recovered 30,766 ETH via a temporary upgrade of the L1 Delayed Inbox.
  • The attack is attributed to TraderTraitor, the North Korean subunit of Lazarus.

A 2,000 ETH lawsuit filed in Canada

Evercrest Technologies, KelpDAO’s parent company, filed a complaint in the British Columbia Supreme Court against LayerZero Labs Ltd., LayerZero Labs Canada Inc. and Bryan Pellegrino, the protocol’s co-founder, who is named in his personal capacity. Three causes of action are alleged: negligent misrepresentation, negligence and defamation. Evercrest seeks compensatory, aggravated and punitive damages, along with a 2,000 ETH contribution aimed at restoring rsETH’s backing.

Since the exploit, more than $650M in assets have been withdrawn from KelpDAO by concerned users. Pellegrino publicly responded on X that the allegations were “baseless” and that he would defend himself in Vancouver. None of the allegations have been tested on the merits, and no response to the complaint has yet been filed.

A single DVN at the heart of the setup

The attack occurred on April 18, 2026 at approximately 17:35 UTC. The attacker unlocked 116,500 rsETH, worth roughly $292M at the time, from KelpDAO’s OFTAdapter contract on Ethereum. A second attempt involving 40,000 rsETH was blocked by KelpDAO’s emergency multisig 46 minutes after the initial drain.

According to Evercrest, the exploit was not the result of an internal failure but of LayerZero’s security infrastructure. The protocol had reviewed and approved the 1-of-1 decentralized verifier network (DVN) configuration used on the Unichain bridge. Multiple documents allegedly prove that LayerZero publicly endorsed this choice.

  • On February 2, 2024, LayerZero told Evercrest the code was “good” and that there was “no issue” using the default DVN configuration.
  • On March 21, 2024, LayerZero explicitly directed Evercrest toward the 1-of-1 setup using its own verifier.
  • In January 2025, LayerZero assured that even if a verifier was compromised, the worst outcome would be an incorrectly verified message.

“Nobody should rely on a single DVN.”

Bryan Pellegrino, co-founder of LayerZero

The complaint stresses that LayerZero never warned KelpDAO of the specific risk attached to a 1-of-1 DVN. By contrast, USDT0 reportedly received a comparable warning in late 2024 or early 2025, prompting it to run its own DVN. Evercrest claims it never received a similar heads-up.

Technical mechanism: RPC poisoning

LayerZero’s analysis, published on April 20, identifies an RPC poisoning attack mechanism, ruling out a key theft, a DVN compromise or a smart contract bug. On March 6, malware was installed on a LayerZero developer’s computer. The attacker then manipulated LayerZero’s nodes to feed false readings to the verifier, before using DDoS to disable uncompromised third-party nodes on April 18.

Dependent on these RPC endpoints to verify the source chain’s state, the DVN was forced to read the poisoned data confirming a fictitious lock of 116,500 rsETH on Unichain. The compromised nodes continued serving accurate data to every other system, keeping the attack invisible until the drain was executed.

LayerZero attributes the operation, with preliminary confidence, to the TraderTraitor subunit of the North Korean Lazarus Group. This attribution follows the Drift exploit on April 1, which cost $285M. In 18 days, the group is linked to roughly $575M drained from DeFi via two structurally different attack vectors, neither involving a smart contract bug.

Massive DeFi fallout

Within 48 hours, DeFi’s total value locked fell by approximately $13B, from $99.5B to $86.3B. Aave shouldered most of the outflows, losing $8.45B in two days and its position as the top protocol by deposits. WETH utilization hit 100% within hours of the attack, with roughly $5.1B in stablecoin deposits facing withdrawal constraints.

Protocol / MetricBefore the attackAfter the attack (48h)Change
Total DeFi TVL$99.5B$86.3B-13B
Aave TVL$26.4B$17.9B-8.45B
Aave WETH utilizationnormal100%saturated
rsETH bad debt (uniform)n/a$123.7Mn/a
rsETH bad debt (isolated L2)n/a$230.1Mn/a

The Arbitrum precedent: recovering ETH through a fork

After the drain, the attacker deposited the 116,500 rsETH as collateral on Aave V3 to borrow WETH, creating an effectively un-liquidatable position that left Aave with unrecoverable debt. The borrowed assets were swapped into ETH and split: 75,700 ETH on Ethereum and 30,765 ETH on Arbitrum. Approximately 89,567 rsETH remain locked on Aave as collateral across both chains.

On April 21 at 23:26 ET, the Arbitrum Security Council (12 members) executed a 9-of-12 vote to recover the 30,766 ETH bridged to Arbitrum. Rather than freezing the attacker’s address, the Council temporarily upgraded the L1 Delayed Inbox, added a function capable of sending cross-chain messages on behalf of any address without its private key, forged a message transferring the ETH to a burn address controlled by the protocol, then reverted the contract to its original state. The funds now sit in a frozen intermediate wallet, movable only via a subsequent vote by ARB holders.

Cascading protocol responses

Aave’s 5-of-9 Protocol Emergency Guardian froze rsETH and wrsETH markets across all deployments at 18:52 UTC. On Aave V4, the protocol’s Security Council disabled supply and borrowing on the Ethereum Core Hub and the Kelp E-Spoke via configuration updates. By Tuesday morning, WETH markets on Ethereum Core V3 had partially reopened but remained at 100% utilization.

  • SparkLend, Fluid, Upshift: froze rsETH markets
  • Lido: suspended earnETH deposits
  • Ethena: temporarily suspended LayerZero OFT bridges from Ethereum mainnet
  • Pendle: suspended principal and yield token markets on rsETH
  • Yearn: froze vaults with rsETH allocations
  • Curve Finance and BitGo: suspended specific functions
  • Morpho: net outflows despite only $1M rsETH exposure across two isolated markets

KelpDAO also announced the abandonment of its sbUSD stablecoin project and has begun migrating rsETH to an alternative cross-chain security standard. The lawsuit will be lengthy, but it crystallizes a foundational question: does the tacit endorsement of a configuration by an infrastructure provider constitute binding liability?


Conclusion

Beyond the legal battle, this case sets a precedent for the entire interoperability sector. If the Canadian courts recognize LayerZero’s liability for endorsing a 1-of-1 DVN without warning, every infrastructure protocol will need to rethink the nature of their technical certifications and public communications. Conversely, a LayerZero victory could normalize the idea that an oral or written recommendation does not constitute enforceable guidance.

The other open question concerns Aave’s bad debt. Will AAVE holders vote to socialize the loss across all depositors or isolate it to the rsETH market? Either outcome will weigh on DeFi protocol governance for years to come.

Sources

This article is published for informational and educational purposes. It does not constitute investment advice. Do your own research (DYOR) before making any decision.

Telemac
Telemachttp://cryptoinfo.ch
Passionné de nouvelles technologies, j’explore l’univers de la blockchain et des cryptomonnaies pour partager l’actualité et les innovations du secteur.

Read More

Items