The KelpDAO LayerZero lawsuit is now public. KelpDAO, operating under the entity Evercrest, has filed a civil claim against LayerZero and its co-founder Bryan Pellegrino. The case centers on the April 18 exploit that drained 116,500 rsETH, worth about $292 million, from a cross-chain bridge. KelpDAO says the bridge's single-verifier setup, known as a 1-of-1 DVN configuration, opened the door for the theft.

Source: Official Announcement
This is one of the largest DeFi security disputes to reach a courtroom this year, and it raises a question the industry has avoided for a long time: who is responsible when shared infrastructure fails.
The complaint makes two core claims. First, LayerZero failed to disclose known weaknesses in its technology. Second, LayerZero's own infrastructure was breached, allowing attackers to forge a valid cross-chain message.
Key claims in the filing:
LayerZero gave written approval for KelpDAO's 1-of-1 verifier setup
That setup was widely used across many LayerZero-linked applications, not a one-off choice
LayerZero later blamed KelpDAO's configuration instead of its own compromised nodes
Kelp DAO paused its contracts quickly once the exploit was detected, limiting further losses
Investigators tied the attack to social engineering that began weeks earlier, eventually compromising internal verifier nodes. Attackers, linked to North Korea's Lazarus Group, then forced reliance on those compromised nodes and pushed through a forged transaction.
Quick facts on the exploit as per the official report:
Tokens stolen: 116,500 rsETH
Value at the time: about $292 million
Share of rsETH's circulating supply: roughly 18%
Attack method: RPC node compromise plus a forged cross-chain message
Pellegrino has rejected the lawsuit outright, calling the claims meritless and confirming LayerZero will defend the case in Vancouver. LayerZero's own position is that KelpDAO chose the single-verifier setup against better guidance, not that LayerZero endorsed it as safe.

Source: X Official
Since the exploit, LayerZero has:
Replaced the compromised verifier nodes
Stopped signing messages for any new single-verifier setups
Pushed integrated projects toward multi-verifier redundancy
Brought in outside security firms to review the incident
KelpDAO, meanwhile, has already moved rsETH to Chainlink's CCIP, which requires multiple independent validators instead of one.
Suing an infrastructure provider after a hack is not new to crypto, even if this exact setup is unusual. A few earlier cases show the range of outcomes:
After Ronin's validator keys were compromised in a large bridge hack, the parent company covered losses and negotiated recovery funding rather than fighting a long court battle
Some claims against Uniswap were dismissed in part because courts treated the protocol as decentralized code rather than a controlling party, a defense LayerZero could try to use here
A separate legal fight already broke out this year over roughly $71 million in frozen funds tied to this same exploit, after other parties sued to unfreeze assets held by Arbitrum's Security Council
Court fights over shared crypto infrastructure rarely go the full distance. Settlements tend to happen once discovery starts putting written agreements and internal messages on the record.
Direct precedent for this kind of case is thin. Broader patterns from past DeFi hack litigation point to three likely paths: an early settlement to stop ongoing reputational damage, a partial liability finding tied to the written endorsement, or a dismissal if the court treats the verifier configuration as KelpDAO's own choice. Full recovery of the entire $292 million from LayerZero looks unlikely given how both sides have framed the facts so far.
What happens next depends heavily on what discovery uncovers. If KelpDAO can produce clear written approval of the 1-of-1 setup, that single document could carry more weight than any technical argument about server control. Either way, the KelpDAO LayerZero lawsuit is shaping up as a reference case for how DeFi projects write, and enforce, security agreements with the infrastructure they depend on.
Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Crypto markets carry significant risk. Always do your own research before making any investment decisions.