KelpDAO has filed a lawsuit against interoperability protocol LayerZero and its co-founder Brian Pellegrino, alleging that undisclosed vulnerabilities in LayerZero's technology paved the way for a $292 million exploit — the largest crypto hack recorded so far in 2026.
The Allegations
The cross-chain lending protocol claims that LayerZero and Pellegrino were aware of weaknesses in their messaging infrastructure but failed to disclose them to partners and users relying on the system. According to the complaint, that alleged silence created the conditions for one of the year's most damaging security breaches.
KelpDAO argues that the missing disclosures directly contributed to the loss of funds, positioning the case as a test of whether infrastructure providers can be held legally responsible when protocols built on top of their technology are drained.
A $292 million breach has become the flashpoint for a legal battle over who bears responsibility when cross-chain infrastructure fails.
The dispute highlights the tangled web of dependencies that defines decentralized finance, where lending platforms, bridges, and messaging layers are stitched together — and where a single flaw can cascade across multiple projects.
Why It Matters
Cross-chain bridges and interoperability layers have long been among the most frequently targeted components in crypto, given the large sums they route between blockchains. A breach of this scale reinforces those concerns and raises fresh questions about accountability in an industry that prizes decentralization.
The case could set an important precedent for how liability is assigned in DeFi. Key questions likely to surface include:
- Whether infrastructure providers owe a duty to disclose known risks
- How responsibility is divided between protocols and the platforms they integrate
- What legal recourse victims of large-scale exploits actually have
As of now, LayerZero and Pellegrino have not been shown to have responded publicly to the claims. The outcome of the litigation may shape how future security failures are handled across the broader crypto ecosystem, particularly as regulators and courts increasingly scrutinize on-chain risk.
