KelpDAO Sues LayerZero Over $292 Million Cross-Chain Exploit
Cross-chain lending protocol alleges LayerZero and co-founder Brian Pellegrino concealed protocol vulnerabilities that enabled the largest hack of 2026.

Sofia Marquez
Regulation & Tech Editor, RefreshCoin
KelpDAO has filed a lawsuit against LayerZero and its co-founder Brian Pellegrino seeking damages for a $292 million exploit that struck the cross-chain lending protocol earlier this year. The complaint alleges that LayerZero failed to disclose critical vulnerabilities in its interoperability infrastructure despite knowing about them before the attack occurred.
What triggered the $292 million exploit?
The exploit originated from a flaw in LayerZero's message verification system that allowed an attacker to forge cross-chain messages and drain assets from KelpDAO lending pools. According to court filings, the vulnerability existed in the protocol's ultra-light node configuration, which relies on a decentralized oracle and relayer pair to validate messages between chains. The attacker manipulated this verification process to execute unauthorized withdrawals across multiple networks simultaneously.
Blockchain analytics firms traced the stolen funds through a series of bridges and decentralized exchanges before they were partially frozen by stablecoin issuers. The hack affected users on Ethereum, Arbitrum, Optimism, and BNB Chain, with the largest single loss occurring on the Ethereum mainnet. KelpDAO estimates that roughly 60 percent of the stolen assets remain recoverable if legal action proceeds quickly.
Why is KelpDAO targeting LayerZero directly?
KelpDAO argues that LayerZero had a contractual and fiduciary obligation to disclose known security weaknesses because the lending protocol relied entirely on LayerZero's messaging layer for cross-chain operations. The complaint cites internal communications suggesting LayerZero engineers identified the vulnerability during a routine audit weeks before the exploit but did not notify integration partners. KelpDAO claims this silence constitutes negligence and fraudulent concealment under Delaware law.
LayerZero has not issued a formal response to the allegations as of the filing date. In previous public statements, the company has emphasized that its infrastructure is permissionless and that integrators assume responsibility for their own risk management. Legal observers note that the outcome may hinge on whether the court treats LayerZero as a service provider with disclosure duties or as a public utility-like protocol with limited liability.
Background on LayerZero's cross-chain architecture
LayerZero launched in 2022 as an omnichain interoperability protocol designed to replace trusted bridges with a lightweight messaging layer. The system uses ultra-light nodes that verify block headers on-chain through a combination of decentralized oracles and relayers, reducing the trust assumptions required for cross-chain transfers. By 2025, LayerZero had integrated with over 50 blockchains and secured more than $15 billion in total value locked across its ecosystem.
The protocol's native token ZRO debuted in mid-2024 and quickly became a top-50 asset by market capitalization. LayerZero's architecture has been adopted by major lending markets, decentralized exchanges, and stablecoin issuers seeking native cross-chain functionality. However, the protocol has faced scrutiny after several smaller exploits in 2023 and 2024 that were attributed to oracle misconfiguration rather than core code defects.
Market context: cross-chain bridge security in 2026
Cross-chain bridges and messaging layers have consistently ranked as the highest-risk category in DeFi since 2022, accounting for over 60 percent of total value stolen from protocols according to industry trackers. The KelpDAO exploit surpasses the previous 2026 record of $180 million lost in a single incident involving a multi-chain yield aggregator. Regulators in the United States and European Union have signaled increased focus on bridge operators following a series of high-profile hacks.
Insurance protocols covering smart contract risk have seen claim payouts rise 40 percent year-over-year, driving premiums higher for protocols relying on external messaging layers. Some lending markets have begun migrating to alternative interoperability solutions such as Wormhole, Axelar, or native chain-specific bridges to diversify infrastructure risk. The KelpDAO case may accelerate this trend if courts impose liability on messaging layer providers.
What the lawsuit means for DeFi liability standards
Legal experts describe the case as a potential landmark for establishing duty-of-care standards in decentralized infrastructure. Most DeFi protocols operate through open-source code with disclaimers that shift all risk to users, but infrastructure layers like LayerZero occupy a gray zone between public goods and commercial service providers. A ruling in favor of KelpDAO could compel messaging protocols to implement formal disclosure programs for discovered vulnerabilities.
Venture investors in cross-chain infrastructure are monitoring the case closely. Several funds have reportedly paused new commitments to messaging layer projects pending clarity on legal exposure. The Blockchain Association and other industry groups have filed amicus briefs arguing that imposing traditional liability frameworks on permissionless protocols would stifle innovation and drive development offshore.
Key dates and catalysts to watch
The initial hearing on LayerZero's motion to dismiss is scheduled for November 2026 in the Delaware Court of Chancery. Discovery could reveal internal security audits, communication logs, and vulnerability disclosure timelines that shape the factual record. A parallel class action on behalf of individual KelpDAO users has been consolidated with the main case, expanding the potential damages pool.
Separately, the SEC's enforcement division has requested documents from both parties as part of an informal inquiry into whether LayerZero's token sale or ongoing operations implicate securities laws. The Commodity Futures Trading Commission has also signaled interest in whether cross-chain messaging layers constitute facilities of interstate commerce subject to its jurisdiction. Market participants should track court filings, regulatory correspondence, and any settlement negotiations that could resolve the matter before trial.
Frequently asked questions
How much money was stolen in the KelpDAO exploit?
The exploit resulted in $292 million in losses across multiple blockchain networks, making it the largest DeFi hack recorded in 2026 so far.
What specific vulnerability did the attacker exploit?
The attacker exploited a flaw in LayerZero's ultra-light node message verification system, forging cross-chain messages to authorize unauthorized withdrawals from KelpDAO lending pools.
Has LayerZero responded to the lawsuit?
As of the filing date, LayerZero has not issued a formal response to the allegations in court or through public channels.
Comments(0)
No comments yet. Be the first to weigh in.