Buy
Market
🔥
Prediction Market

Breaking Down KelpDAO Developments for Market Participants

BiFu Editorial · 2026-09-26 · 5 min read


Table of contents

KelpDAO sued LayerZero and CEO Bryan Pellegrino after the April 18 exploit drained $292 million in rsETH, alleging the bridge's single-verifier setup was endorsed in writing. LayerZero dismissed the claim as meritless, leaving the legal outcome and warning details unresolved pending discovery.

KelpDAO developments now center on a lawsuit that could reshape how cross-chain protocols approve security configurations. On April 18, an exploit drained $292 million in rsETH, and KelpDAO has sued LayerZero and CEO Bryan Pellegrino, alleging the bridge setup was endorsed in writing. The suit claims that written endorsement contributed to the exploit, a charge LayerZero has dismissed as meritless.

This legal action marks a rare instance where a protocol's written approval becomes the focal point of a major security dispute, affecting developers, auditors, and users who rely on cross-chain infrastructure.

KelpDAO developments: Four sources confirm the lawsuit details

According to CoinDesk, KelpDAO sued LayerZero for what it describes as the largest exploit 2026 has seen so far. The cross-chain lending protocol accused LayerZero and co-founder Brian Pellegrino of failing to disclose weaknesses in their protocol, which led to the $292 million hack. Cointelegraph reports that KelpDAO says LayerZero endorsed its bridge setup before the attack, while CEO Bryan Pellegrino has dismissed the lawsuit as meritless.

Decrypt adds that Evercrest, a developer associated with KelpDAO, says LayerZero approved the single-verifier configuration in writing multiple times, then warned a different developer about it. The Block confirms that KelpDAO sued LayerZero and Bryan Pellegrino over the April 18 rsETH exploit, alleging the bridge setup was endorsed in writing.

The single-verifier configuration, which relies on one party to validate cross-chain messages, is a known risk vector in the industry. KelpDAO's argument is not just that the exploit happened, but that LayerZero's written approval created a false sense of security. The lawsuit names specific communications, alleging that warnings were issued to a different developer, not to KelpDAO. This detail, reported by Decrypt, suggests a breakdown in communication that could have operational consequences for how protocols verify security recommendations.

Shared operating impact for the named participants

The affected participants include KelpDAO users who held rsETH, LayerZero's broader user base, and any developer relying on bridge endorsements. The operational consequence is that cross-chain protocols may now face heightened scrutiny over how they approve and communicate security configurations. For BiFu readers, this means staying informed about bridge security practices and understanding that even written approvals do not eliminate risk.

The lawsuit also signals a potential shift in how legal responsibility is assigned in decentralized finance, where code is often treated as law but human decisions still carry weight.

LayerZero's dismissal of the claim as meritless leaves the legal outcome uncertain, but the operational takeaway is clear: written approvals are not a substitute for thorough security audits. The incident also underscores the need for protocols to document every security decision, as these records can become central in disputes.

What remains unresolved and the next source-document check

What remains unresolved is whether the court will accept KelpDAO's argument that written endorsement constitutes a binding security guarantee. LayerZero's position, as reported by The Block, is that the lawsuit lacks merit, but no court ruling has been issued. The timing of the warnings, the content of the written approvals, and the role of the different developer mentioned by Evercrest are all facts that could emerge during discovery.

Until then, the industry is left with a cautionary tale about the limits of written security endorsements.

The broader implication for cross-chain security is that protocols must move beyond relying on a single verifier, regardless of who approved it. KelpDAO's decision to sue is a concrete step, but it does not restore the lost funds or prevent similar exploits. For BiFu readers, the practical takeaway is to assess bridge security independently, rather than assuming that a provider's written approval guarantees safety. Following this case closely will reveal whether legal precedent catches up with the pace of DeFi innovation.

Source-document check required: The exact content of the written approvals, the timing of LayerZero's warnings to the other developer, and any internal communications between Evercrest and LayerZero remain unverified from the source documents. These details will likely emerge during the discovery phase of the lawsuit.

Reference

  • https://www.coindesk.com/business/2026/09/25/kelpdao-sues-layerzero-for-the-largest-exploit-2026-has-seen-so-far
  • https://cointelegraph.com/news/kelpdao-layerzero-lawsuit-rseth-exploit
  • https://decrypt.co/379288/kelpdao-developer-sues-layerzero-over-292m-bridge-exploit
  • https://www.theblock.co/news/regulation/2026-09-25-kelpdao-sues-layerzero-claims-it-endorsed-setup-used-in-292-million-rseth-exploit-416361

Read more from BiFu

KelpDAO sued LayerZero and CEO Bryan Pellegrino after the April 18 exploit drained $292 million in rsETH, alleging the bridge's single-verifier setup was endorsed in writing. LayerZero dismissed the claim as meritless, leaving the legal outcome and warning details unresolved pending discovery.

Learn More