KelpDAO has filed a lawsuit against cross-chain messaging protocol LayerZero and its CEO, Bryan Pellegrino, following a $292 million exploit tied to its rsETH bridge. The liquid restaking platform alleges that LayerZero endorsed its bridging configuration before the attack, a claim the LayerZero chief has flatly rejected.
## The Allegations KelpDAO contends that LayerZero reviewed and approved the bridge setup that was later compromised, framing the endorsement as central to its decision to deploy the system. The restaking protocol argues that responsibility for the vulnerability should not rest solely on its shoulders given the alleged sign-off.
The dispute centers on the security of the infrastructure used to move rsETH, KelpDAO's restaked ether token, across different blockchain networks. Bridges have long been among the most targeted components in crypto, repeatedly exploited for large sums because they concentrate liquidity across chains.
A $292 million exploit has now spilled into a courtroom battle between two crypto infrastructure players.
## LayerZero Pushes Back Pellegrino has publicly dismissed the lawsuit as meritless, signaling that LayerZero intends to contest the claims rather than settle. His stance suggests the company disputes both the notion that it endorsed the setup in a legally binding way and any liability for the resulting losses.
The legal fight highlights the growing tension over accountability when cross-chain systems fail. As protocols increasingly rely on third-party messaging and bridging services, questions about who bears responsibility for security failures have become more pressing across the industry.
Key points in the emerging dispute include:
- KelpDAO says LayerZero approved its bridge configuration before the exploit
- The attack resulted in roughly $292 million in losses tied to rsETH
- Pellegrino has called the lawsuit meritless and appears ready to fight it
The outcome could set a notable precedent for how liability is assigned between DeFi projects and the infrastructure providers they depend on, especially as bridge exploits continue to rank among the costliest incidents in the sector.
