Table of Contents
The Lawsuit Claims LayerZero Endorsed a Vulnerable Configuration

KelpDAO filed a lawsuit against LayerZero and co-founder Bryan Pellegrino over an April 18 exploit that drained 116,500 rsETH worth approximately $292 million. The lawsuit alleges LayerZero reviewed and endorsed the configuration used by the exploited bridge while failing to disclose related security risks. This represents the largest exploit of 2026 and one of the most significant legal actions between DeFi protocols over cross-chain infrastructure liability.
According to the lawsuit, Evercrest, the bridge operator contracted by KelpDAO, claims LayerZero provided written communications on February 2, 2024, stating there was "no problem" with using the default DVN configuration. On March 21, 2024, LayerZero allegedly directed Evercrest to use the same 1-of-1 configuration as another bridge. The April 22 attack that followed drained 116,500 rsETH and contributed to a broader liquidity crisis that erased $20 billion in decentralized finance deposits.
Bryan Pellegrino disputed the allegations publicly. "The claim continues to be meritless," he stated on X, adding that he would defend himself accordingly. The case will test whether protocol developers bear liability for endorsed configurations that prove vulnerable, setting precedent for how responsibility is allocated when decentralized bridge security fails.
The Income Context for DeFi Yield Strategists

This exploit matters for readers pursuing DeFi yield strategies because it illustrates how bridge security failures translate directly into capital loss that eliminates yield opportunity entirely. Liquid staking derivatives like rsETH enable capital efficiency by allowing stakers to use their staked assets as collateral across multiple protocols. The income mechanic works when the derivative maintains its peg and liquidity remains stable. When a bridge exploit drains liquidity and triggers a de-peg event, the entire yield surface collapses.
Evercrest reported that KelpDAO users have withdrawn more than $650 million in assets since the exploit, representing a classic liquidity run dynamic. For yield strategists, this withdrawal cascade matters because it demonstrates how bridge exploits produce second-order income destruction beyond the initial loss. Users who were earning staking yields plus additional protocol incentives on their rsETH positions lost access to both income streams when liquidity dried up and the token became difficult to exit.
The lawsuit's focus on LayerZero's alleged endorsement of the vulnerable configuration raises a critical question for income-focused DeFi participants: who verifies the security assumptions underlying the cross-chain infrastructure that enables yield strategies? Most users deploying capital into liquid staking derivative strategies assume that bridge operators have conducted proper due diligence on the messaging protocols they integrate. This case suggests that assumption may not hold, and that protocol endorsements may not carry the liability weight users expect.
How Bridge Configuration Economics Actually Work

The technical detail at the center of this lawsuit is the 1-of-1 DVN (Decentralized Verifier Network) configuration. In LayerZero's architecture, DVNs verify cross-chain messages before they are executed on the destination chain. A 1-of-1 configuration means a single verifier node can authorize message execution. This creates a single point of failure: if that one verifier is compromised or malicious, it can authorize fraudulent messages that drain bridge liquidity.
More secure configurations use multi-signature setups, such as 3-of-5 or 5-of-9, requiring multiple independent verifiers to sign off on a message before execution. The income trade-off is real but not typically visible to end users. Multi-signature configurations cost more to operate because they require coordinating multiple verifiers, which translates to higher bridge fees. Single-verifier configurations are cheaper to run and can process messages faster, which is why some bridge operators adopt them despite the security risk.
For DeFi yield strategists, this trade-off matters because the bridge fee differential between 1-of-1 and multi-signature configurations is typically measured in basis points per transaction, while the exploit risk differential can be total loss. The $292 million rsETH exploit represents a catastrophic outcome that no fee savings could justify. Yet the lawsuit alleges LayerZero endorsed the vulnerable configuration, suggesting the protocol may have prioritized operational efficiency over security margin.
The lawsuit also raises questions about who bears the economic cost when endorsed configurations fail. If KelpDAO prevails, it could establish that cross-chain messaging protocols carry liability for configurations they recommend, even when the bridge operator makes the final implementation decision. That would shift the security verification burden from individual bridge operators to the infrastructure layer, potentially increasing the due diligence requirements and associated costs for messaging protocols.
What This Means for Liquid Staking Yield Strategies
Liquid staking derivatives represent one of the most capital-efficient yield strategies in DeFi because they allow users to earn staking rewards while simultaneously deploying the derivative as collateral in lending markets, liquidity pools, or other yield-bearing protocols. The rsETH exploit demonstrates how cross-chain bridge failures can destroy this capital efficiency entirely. When the bridge was exploited and 116,500 rsETH was drained, users holding rsETH on the destination chain faced immediate liquidity constraints as the token de-pegged and withdrawal queues extended.
For yield strategists, the practical lesson is that cross-chain liquid staking positions carry bridge risk that is often invisible in the yield calculation. A user earning 4% staking yield plus 6% protocol incentives on their rsETH position might see that as a 10% annual return, but that calculation does not account for the probability-weighted expected loss from bridge exploits. The $292 million loss represents roughly 40% of the peak rsETH supply, meaning users who were deployed across the bridge lost not just their accumulated yield but a substantial portion of their principal.
The $650 million in withdrawals that followed the exploit also illustrates how bridge failures trigger liquidity cascades that eliminate future yield opportunities. As users withdrew from KelpDAO protocols, the total value locked declined, which reduced the protocol's ability to offer competitive incentives. This created a self-reinforcing cycle where declining yields prompted further withdrawals, which further reduced yields. For income-focused participants, this dynamic means that bridge exploits represent not just immediate capital loss but also the destruction of future yield surface in the affected protocols.
The lawsuit's outcome could influence how future liquid staking protocols structure their cross-chain integrations. If courts establish that messaging protocols bear liability for endorsed configurations, we may see more conservative bridge designs with multi-signature verifier setups as the default. That would likely increase bridge costs but reduce catastrophic failure risk, changing the risk-return profile for cross-chain yield strategies in a direction that favors capital preservation over marginal fee savings.
Legal Precedent and Protocol Liability Questions
This lawsuit represents the first major legal action between DeFi protocols over cross-chain infrastructure liability, and its outcome will establish precedent for how responsibility is allocated when decentralized bridge security fails. The central legal question is whether LayerZero's alleged written endorsement of the 1-of-1 configuration creates liability when that configuration is subsequently exploited. If KelpDAO prevails, it would establish that protocol-level recommendations carry legal weight, even in nominally decentralized systems where the bridge operator makes final implementation decisions.
The practical implication for yield strategists is that protocol endorsements may gain enforceable meaning, which could change how infrastructure providers communicate about security configurations. If messaging protocols face liability for configurations they recommend, they will likely become more conservative in their guidance, potentially refusing to endorse any single-verifier setups regardless of the operational trade-offs. That would increase the baseline security standard for cross-chain bridges, but it might also reduce the diversity of configuration options available to bridge operators who are optimizing for different risk-return profiles.
The lawsuit also raises questions about disclosure requirements for cross-chain infrastructure. KelpDAO alleges that LayerZero failed to disclose related security risks when it endorsed the 1-of-1 configuration. If courts find that infrastructure protocols have a duty to disclose known risks associated with configurations they endorse, we may see more detailed security documentation emerge across the cross-chain messaging sector. For yield strategists, better disclosure would make bridge risk more visible and measurable, allowing for more accurate risk-adjusted return calculations.
Bryan Pellegrino's public response that the claim is "meritless" suggests LayerZero will argue that bridge operators bear full responsibility for security configuration decisions, regardless of any guidance the messaging protocol provided. This defense position, if successful, would leave the liability allocation framework unchanged: bridge operators remain solely responsible for security outcomes, and infrastructure protocols face no liability for endorsed configurations. That would preserve the current state where yield strategists must independently verify bridge security assumptions rather than relying on infrastructure-level endorsements.
Bridge Security Due Diligence for Yield Deployment
The rsETH exploit provides a clear case study in the specific security checks yield strategists should run before deploying capital across cross-chain bridges. The first check is verifier configuration: how many independent nodes must sign off on a cross-chain message before it executes? Single-verifier setups like the 1-of-1 configuration allegedly used in the rsETH bridge represent unacceptable single points of failure for any serious capital deployment. Multi-signature configurations with at least three independent verifiers provide substantially better security, and configurations with five or more verifiers approach the security margins used by established cross-chain protocols.
The second check is verifier identity and independence. Even a 5-of-9 multi-signature setup provides limited security if all nine verifiers are controlled by the same entity or selected from a single trust set. Effective multi-signature security requires verifiers that are economically, operationally, and jurisdictionally independent, so that compromising the threshold number of verifiers requires separate attacks against separate entities. The lawsuit does not specify whether the single verifier in the rsETH bridge configuration was controlled by the bridge operator, the messaging protocol, or a third party, but that identity question matters enormously for security evaluation.
The third check is messaging protocol track record and security posture. LayerZero has faced scrutiny over its security practices before, and the current lawsuit adds to that record. For yield strategists, protocol track record functions as a proxy for the quality of security guidance and the likelihood that endorsed configurations have been properly vetted. Protocols with clean security records and transparent security documentation provide higher confidence that their endorsed configurations reflect actual security analysis rather than operational convenience.
The fourth check is liquidity depth and withdrawal capacity on both sides of the bridge. Even if a bridge configuration appears secure, concentrated liquidity creates exit risk when exploits or de-peg events occur. The $650 million in withdrawals following the rsETH exploit demonstrates how quickly liquidity can drain when user confidence breaks. Yield strategists deploying significant capital should verify that bridge liquidity on both the source and destination chains can support their full position exit without material slippage, and should monitor that liquidity continuously rather than assuming it will remain stable.
The Takeaway
The KelpDAO lawsuit against LayerZero over the $292 million rsETH bridge exploit establishes that cross-chain infrastructure liability is now a contested legal question with real financial stakes for DeFi yield strategists. The case tests whether messaging protocols bear responsibility for security configurations they endorse, and the outcome will determine whether yield strategists can rely on protocol-level guidance or must independently verify every bridge security assumption. For anyone deploying capital into liquid staking derivatives or other cross-chain yield strategies, the rsETH exploit demonstrates that bridge configuration details like verifier count and independence are not abstract technical questions but direct determinants of capital preservation. The specific check that matters most: verify the verifier configuration before you bridge, and if the answer is 1-of-1, the correct response is to find a different bridge or keep your capital on the source chain.
Frequently Asked Questions
What was the rsETH bridge exploit and how much was lost?
On April 18, 2026, an exploit targeting a bridge used by KelpDAO drained 116,500 rsETH worth approximately $292 million. The attack exploited a 1-of-1 verifier configuration in the LayerZero messaging protocol, allowing a single compromised verifier to authorize fraudulent cross-chain messages. This represents the largest exploit of 2026 and contributed to a broader DeFi liquidity crisis that erased $20 billion in total value locked across decentralized finance protocols.
Why is KelpDAO suing LayerZero over the bridge exploit?
KelpDAO alleges that LayerZero reviewed and endorsed the bridge configuration that was later exploited, while failing to disclose related security risks. According to the lawsuit, LayerZero provided written communications in February 2024 stating there was no problem with the default verifier configuration, and in March 2024 directed the bridge operator to use the same 1-of-1 setup as another bridge. The lawsuit tests whether messaging protocols bear legal liability for security configurations they endorse, even when bridge operators make final implementation decisions.
What is a 1-of-1 verifier configuration and why is it risky?
A 1-of-1 verifier configuration means a single node can authorize cross-chain message execution without requiring confirmation from other independent verifiers. This creates a single point of failure where compromise of one verifier enables complete bridge control. More secure configurations use multi-signature setups like 3-of-5 or 5-of-9, requiring multiple independent verifiers to approve each message. The security trade-off is substantial: 1-of-1 configurations offer lower costs and faster processing but expose the entire bridge to catastrophic loss if that single verifier is compromised.
How did the exploit affect liquid staking yield strategies?
The exploit destroyed capital efficiency for users holding rsETH across the bridge by draining liquidity and triggering a de-peg event. Users earning staking yields plus protocol incentives lost access to both income streams when the token became difficult to exit and withdrawal queues extended. KelpDAO users subsequently withdrew more than $650 million in assets, creating a liquidity cascade that eliminated future yield opportunities as declining total value locked reduced the protocol's ability to offer competitive incentives. This demonstrates how bridge failures eliminate not just current positions but future yield surface.
What security checks should yield strategists run before using cross-chain bridges?
First, verify the verifier configuration and require at least three independent nodes in a multi-signature setup. Second, check verifier identity and independence to ensure they are economically and operationally separate entities. Third, evaluate the messaging protocol's track record and security documentation to assess whether endorsed configurations reflect actual security analysis. Fourth, verify liquidity depth on both bridge sides can support full position exit without material slippage, and monitor that liquidity continuously. Single-verifier configurations represent unacceptable risk for serious capital deployment regardless of cost or speed advantages.
You have just reviewed the $292 million bridge exploit that tested cross-chain security assumptions for liquid staking yields. The next configuration failure is already deployed somewhere in DeFi infrastructure.
Every Thursday: where crypto yield actually is - stablecoins, liquid staking and DeFi lending, with the risk named next to the rate and what changed since last week.
Get it free every ThursdayFree. No trade calls, no allocations, no hype. Unsubscribe in one click.