(SeaPRwire) –
By: Lucas Caldwell
Here is the thing nobody in crypto wants to say out loud. When LayerZero builds your bridge and attackers steal $292 million from it, you have a problem. Your infrastructure provider is also your largest risk vector. KelpDAO knew this. That is why they filed a lawsuit in British Columbia against LayerZero and CEO Bryan Pellegrino this week. The bridge held 116,500 rsETH. That was about a fifth of all restaked ether in circulation. North Korean hackers drained it in one shot. Now KelpDAO wants LayerZero to pay for the damage they say the protocol’s own technology caused.
On April 22, attackers compromised LayerZero’s internal nodes and tricked a single verifier into approving a fake cross-chain message. KelpDAO’s bridge relied on that one verifier as its only checkpoint. No second signature, no independent cross-check. The forged message went through and released funds instantly. The theft hit fast and total. LayerZero later published an incident report pointing exactly at this single-point-of-failure setup. They said they had already recommended multi-verifier configurations. But KelpDAO disputes this framing entirely. The company says LayerZero had a duty to warn it about the setup’s weaknesses.
KelpDAO claims they discussed the verifier setup with LayerZero months before the attack. They say they received written confirmation that it was secure. The lawsuit filed in British Columbia states the exploit was a direct result of LayerZero’s failures to disclose known risks. Pellegrino responded quickly on social media. He called the claim meritless and vowed to fight it in a Vancouver court. The blast radius was massive. Aave borrowed $300 million to cover withdrawal surges. Total value locked across DeFi evaporated by $20 billion within days.
This lawsuit exposes a fracture line in the entire cross-chain interoperability market. Every bridge protocol selling to DeFi projects carries an implicit promise. Your money moves safely between chains because our technology guarantees it. But when that guarantee breaks and hundreds of millions walk away, who absorbs the loss? LayerZero’s model treats projects as users of a service. Not clients bound by a duty of care. KelpDAO just challenged that assumption in a courtroom. The industry has never faced this test before. The answer will define how every major protocol prices risk from now on.
KelpDAO has already moved its rsETH bridge to Chainlink’s Cross-Chain Interoperability Protocol. That migration signals more than a vendor switch. It signals a trust reset across the DeFi infrastructure layer. Every bridge operator now has a client showing up with a lawsuit and a migration plan. The question is not whether LayerZero survives this. The question is whether other interoperability protocols harden their architectures fast enough. The North Korean group behind this attack is still operating. They will be back. The next bridge they target will reveal which protocols are built for war versus marketing decks.
The next bridge hack will not arrive with a lawsuit attached, no warning, no disclosure, and no recourse.
Author bio: Lucas Caldwell, a tech opinion leader with millions of followers on X/Twitter, focuses on DeFi infrastructure risks, cross-chain protocol vulnerabilities, and the legal gray zones reshaping crypto accountability.