InvestigationLayerZeroKelp DAOrsETH

Kelp DAO v. LayerZero: what the blockchain shows

One forged message emptied a bridge in April. Now the firm behind the bridge is suing the firm whose software approved it, and much of what they dispute sits on public blockchains, where anyone can check it.

At a glance
On April 18, 2026, an attacker got the only verifier on one of Kelp DAO's bridge routes to approve a transfer that never happened, and walked off with 116,500 rsETH, worth about $295 million. Evercrest, the company behind Kelp, is now suing LayerZero, whose software and verifier ran that route, and its chief executive Bryan Pellegrino. We rebuilt the attack, and two years of Kelp's bridge settings, from the blockchain record. Kelp's account of the attack holds up, down to a second try for exactly 40,000 rsETH that its freeze stopped. Part of LayerZero's holds up too. Kelp's own transactions cut several routes from two verifiers to one. Most of the stolen ETH on Ethereum went to Bitcoin through THORChain. On Arbitrum, 30,766 ETH is still frozen.
$294.6M
Value of the 116,500 rsETH paid out on April 18
40,000
rsETH in a second fake message, stopped by Kelp's freeze
24 of 26
Kelp routes into Ethereum on one verifier on the day
83%
rsETH's share of the value relying on one verifier (2.3% of messages)
Key findingsEach line has its own share link
  1. 12.6 hours

    Between Ethereum paying out 116,500 rsETH for Unichain message #308 and the real #308 leaving Unichain. It carried 0.001 rsETH.

  2. 40,000

    rsETH in a second fake message, signed at 18:25 UTC. The attacker tried to collect it twice. Both tries failed on Kelp's freeze.

  3. 8 routes

    Where LayerZero's default used two verifiers and Kelp's own transactions cut it to one. Its Arbitrum route ran on two for seven weeks first.

  4. 18 of 26

    Kelp routes where LayerZero offered no working default, including Unichain, the route that was attacked.

  5. 157 apps

    Received messages into Ethereum checked by LayerZero Labs alone in the seven weeks before. rsETH: 2.3% of messages, 83% of value.

  6. 30,766 ETH

    Frozen on Arbitrum and still held. About 71,200 ETH on Ethereum went to Bitcoin through THORChain.

01 · The payoutA transfer that never happened

On the evening of Saturday, April 18, 2026, a new wallet on Ethereum received 116,500 rsETH. It had been funded that morning with a small amount from Tornado Cash, the mixer. The tokens came out of Kelp DAO's bridge contract. It released them because it had been told the same amount was on its way in from Unichain.

Nothing had left Unichain. Within minutes the rsETH sat in seven wallets. Within two hours the attacker had turned it into about 106,000 ETH, mostly by borrowing against it on Aave, Compound and Euler. At the time it was, in CoinDesk's words, "2026's biggest crypto exploit".

02 · The piecesKelp, rsETH and the verifier

Kelp DAO issues rsETH, a liquid restaking token. You deposit ETH with Kelp and get rsETH back. Kelp stakes and restakes the ETH to earn rewards, and rsETH keeps earning them while you trade it, bridge it or borrow against it. Before the attack there was some $1.6 billion of it.

rsETH lives on Ethereum but is used on 26 other networks. To move it between them, Kelp used LayerZero, a cross-chain messaging protocol that many token teams use as a bridge. When rsETH leaves Ethereum, it is locked in Kelp's bridge contract, the lockbox, and the same amount is minted on the other chain. On the way back the copy is burned and the lockbox releases the original. So the lockbox holds the backing for every rsETH outside Ethereum.

Each of those moves is a message, say, "10 rsETH locked on Unichain, release 10 on Ethereum." Before Ethereum acts on it, at least one verifier has to confirm the lock really happened. Each is called a DVN, short for decentralized verifier network, and every app picks its own. An app can require several, or just one. With one, a single approval releases the funds.

Kelp DAO is built by Evercrest Technologies, a Panama company. LayerZero Labs, based in Vancouver, builds the protocol and runs one verifier.

03 · The lawsuitEvercrest v. LayerZero

On September 24, Evercrest sued LayerZero Labs, its Canadian arm and Bryan Pellegrino, its co-founder and chief executive, in the Supreme Court of British Columbia, as The Crypto Times reported. The claim says the hack was of LayerZero's own systems, and that the company had reviewed and approved Kelp's setup with a single verifier. Then, it says, the company and Pellegrino put the fault on Kelp in public. Evercrest wants damages for negligent misrepresentation, negligence and defamation. None of it has been tested in court.

LayerZero sees it differently. Its incident statement says Kelp's route "relied on a 1-of-1 DVN setup, with LayerZero Labs as the sole verifier", and that more than one verifier is "LayerZero's express recommendation to all integrators". It told CoinDesk that Kelp "deployed multiDVN and then manually downgraded to a 1/1."

A lot of this happened on public chains, so it can be checked. We rebuilt the attack from the Ethereum, Unichain and Arbitrum records, along with every change Kelp made to its bridge settings since early 2024. Evercrest's account of the attack holds up in detail. So does LayerZero's point about the downgrade, on the routes that had a working default. One of Pellegrino's public claims holds only in part. What was said in private, and who is liable, is for the court.

04 · The forgeryHow one approval released $295 million

How a LayerZero bridge message is checkedTokens leave the lockbox on Ethereum only after every required verifier (DVN) confirms the send on the other chain.On April 18 the verifier read Unichain through servers the attacker had tampered with, according to LayerZero's incident report.Two verifiers: Kelp's Arbitrum route, Feb 14 to Apr 1, 2024One verifier: Kelp's Unichain route, April 18, 2026Tokens locked on Arbitrum,message sent to EthereumLayerZero LabssignsGoogle CloudsignsBoth signatures in:lockbox releases rsETHNothing sent from Unichain:its count stays at 307LayerZero Labssigns fake #308One signature is enough:116,500 rsETH releasedno second verifier

Every message on a route carries a nonce, a number that goes up by one each time. The message that emptied the lockbox claimed to be number 308 from Kelp's rsETH contract on Unichain. Two minutes before the payout, LayerZero Labs' verifier approved it. The attacker's own wallet then submitted it on Ethereum and collected.

Unichain says otherwise. Its end of the bridge counts every message it sends, and at the moment of the payout that count stood at 307. Six hours later it still did. The real message 308 left Unichain the next morning, more than 12 hours after the payout, carrying a couple of dollars' worth of rsETH. It never arrived. Its slot on Ethereum was already taken.

The fake approval came from the same wallet that sends the verifier's routine ones, before and after the attack. That fits LayerZero's own incident report. It says the attacker fed the verifier false data through the nodes it used to read other chains. Then the attacker knocked out the outside nodes it could have used instead. The report also says a North Korean group, which it calls TraderTraitor, was behind the attack. None of that shows up on-chain.

What does show up is Kelp's setting for the route, read from Ethereum just before the attack: one verifier, LayerZero Labs, and no backup. One approval was all it took.

05 · The second try40,000 more, 50 minutes later

April 18, 2026: the first hour and a halfTimes in UTC. Each mark is a transaction on Ethereum or Arbitrum.LayerZero verifierAttackerKelp17:3017:4017:5018:0018:1018:2018:3018:4018:50signs fake #308116,500 rsETH out of the lockboxsplits, borrows on Aave and Compound39,743 rsETH bridged to Arbitrum, landed by 18:13freezes the receiving walletsigns fake #309 (40,000 rsETH)two tries to cash #309 failfreezes 7 walletspauses rsETHfreezes the lockbox

The first payout left the lockbox almost empty. Then the attacker did an odd thing. It sent about a third of the rsETH back out of Ethereum, to Arbitrum. Every rsETH that leaves Ethereum gets locked in that same lockbox, so the attacker was filling it back up. With other users' bridging, it soon held just over 40,000 rsETH.

Fifty minutes after the first payout, the same verifier approved a second message from Unichain, number 309. Ethereum stores only a hash of each message, a fingerprint of its contents, so we tried amounts until one matched. It was exactly 40,000 rsETH, to the same wallet as before. The attacker's two failed attempts to collect it show the same amount. Kelp had frozen that wallet in the rsETH contract three minutes before.

Evercrest's claim says Kelp stopped a second theft of "approximately 40,000 rsETH". The record matches, to the token. Kelp's first freeze came about 43 minutes after the payout. Minutes later it paused rsETH, and within half an hour it froze the lockbox itself.

It was not fast enough for everything. The rsETH sent to Arbitrum had already landed there before Kelp's first freeze.

06 · The settingWho chose one verifier, and when

Kelp's 26 rsETH routes into Ethereum: who set one verifierEach row is a route; cells show how many verifiers it required. Defaults read just before Kelp first set each route.MantaModeBlastScrollBaseOptimismLineaX LayerzkSync EraZircuitSwellHemiBerachainSonicMovementHyperEVMTACAvalancheInkPlasmaStableMegaETHMantleMonadRoute fromFirst setLayerZero defaultKelp's first settingOn April 18, 20262024-03-162024-03-192024-03-192024-03-252024-03-252024-04-012024-04-012024-04-152024-05-092024-05-162024-09-112024-12-172024-12-172025-01-242025-03-042025-03-142025-03-282025-04-022025-07-132025-08-182025-09-152025-09-162025-12-102025-12-232026-01-012026-04-01nonenonenonenonenonenonenonenonenonenonenonenonenonenonenonenonenonenone222121112112112112111111111111211112211111121111211111121111ArbitrumUnichain← attacked

Most of the lawsuit is about what came before the attack. How did Kelp's routes end up relying on a single verifier? Every change to a route's verifier list is an on-chain transaction. That let us read the whole history: Kelp's setting on each of its 26 routes into Ethereum, and the default when Kelp first set it.

Kelp's first route, from Arbitrum, went live in February 2024 on LayerZero's default. That meant two verifiers, LayerZero Labs and Google Cloud, and its first 151 messages carry both approvals. Then, on April 1 that year, the admin account on Kelp's bridge switched the Arbitrum and Optimism routes to LayerZero Labs alone. From then on one approval was enough. In all, the default used two verifiers on eight of Kelp's routes, and Kelp's own transactions cut each to one.

That part matches LayerZero's line that Kelp "manually downgraded". Evercrest's claim says Kelp made those changes on the company's advice, in written messages the chain cannot show. One date does line up. The claim says that on March 21, 2024, LayerZero told Kelp to use one verifier on routes that had no default. Early that morning, Kelp moved its Mode and Blast routes from two verifiers to one.

The route that was attacked is a different case. On 18 of Kelp's 26 routes, Unichain among them, there was no working default at all. On Unichain the default verifier was a placeholder that rejects every message with the words "Please set your OApp's DVNs and/or Executor". Kelp had to choose. In April 2025 it opened the Unichain route with LayerZero Labs alone. The route never had another setting until after the attack, just as the claim says.

By the day of the attack, all but two of Kelp's routes into Ethereum ran on one verifier. Five days later Kelp moved every route to four.

07 · How commonWas Kelp alone?

Messages into Ethereum checked by LayerZero Labs alone, March 1 to April 18, 2026157 apps. rsETH's share by number of messages and by the value of the tokens they carried.Tokens valued at market prices of the time. 36 of the apps sent messages with no tokens, so they carry no value here.Messages (6,957)Value of tokens carried ($106.5M)rsETH 2.3%, then all other appsall other appsrsETH 83%

Whether that setup was rare has become its own fight. In May, Pellegrino wrote that "almost 100% of the volume on a 1/1 [configuration] was rsETH", as quoted in Evercrest's claim. Kelp's own memo, as CoinDesk reported, put the share of active apps with one verifier at close to half.

So we counted. In the seven weeks before the attack, some 7,000 messages arrived on Ethereum with an approval from LayerZero Labs alone. They went to 157 apps. We checked the settings of the busiest 15, and every one used that verifier and nothing else, just like Kelp. By number of messages, rsETH was one app among many, with 2.3% of them.

By value it was far ahead. The tokens in those messages were worth $106.5 million, and rsETH was 83% of it. The next largest apps moved a few million dollars each. By value, Pellegrino's point holds. By count, the record does not support it. rsETH carried most of the value that relied on one verifier, but plenty of other apps relied on it too.

08 · The moneyWhere the 116,500 rsETH went

Where the 116,500 rsETH went, and the ETH raised against itLeft: rsETH by first use. Middle: ETH raised on each chain. Right: what became of that ETH.about 71,200 ETH net351 Bitcoin addressesOther routes, about 4,500Security Council,still heldrsETH boxes are scaled to rsETH, ETH boxes to ETH. "Other routes" include Maya, other bridges, a privacy tool and swaps to stablecoins.Aave, Ethereum: 53,400Compound: 17,426Euler: 701Sold on Ethereum: 5,230Bridged to Arbitrum, Aave there: 39,74375,701 ETH30,766 ETHon Ethereumon ArbitrumTo Bitcoin via THORChainFrozen by Arbitrum

Back to April 18. The attacker sold little of the rsETH and borrowed against the rest. The biggest share went into Aave on Ethereum, with more in Compound and Euler. A smaller part was sold outright. The rest was bridged to Arbitrum and posted on Aave there. All told, the attacker raised about 106,000 ETH and gathered it in one address, 0x5d39…7ccc, on both chains.

On Arbitrum the money never left. Early on April 21, 30,766 ETH moved out of that address in a transaction the attacker did not sign. Arbitrum's Security Council said it had frozen the funds, as CoinDesk reported. In June the ETH moved again, to a multisig on Arbitrum, where it still sits.

On Ethereum the attacker waited two and a half days. Then it split about 75,700 ETH across more than a hundred new wallets. From there it swapped the ETH for Bitcoin through THORChain, a protocol that trades coins across chains. About 71,200 ETH went that way once refunds are netted out, most of it within a day and a half, to 351 Bitcoin addresses. Smaller sums went out through other bridges and stablecoins. Scammers, meanwhile, dropped fake "ETH" tokens into look-alike wallets at every step, which makes the trail harder to follow by eye. We counted only real ETH.

09 · The billWho paid

Someone had to cover the hole. The lenders went first. In May, Aave wrote off about 83,000 WETH across Ethereum and Arbitrum and seized the attacker's rsETH collateral for almost nothing. What the attack did to Aave's depositors is its own story, told in The week $12 billion left Aave. Compound was paid for the rsETH stuck in its markets, with WETH from a wallet funded partly by Aave's treasury.

WhoWhat it paid or got back
Aave, Ethereum52,964 WETH written off, May 6
Aave, Arbitrum29,835 WETH and 821 wstETH written off, May 6
CompoundPaid 16,782 WETH for 17,426 rsETH, May 9
Into the recovery wallet2,000 ETH and 5,000 ETH on May 9; 143 ETH from Euler's multisig
Back to the lockbox76,758 rsETH in May: 53,400 from Aave, 17,426 from Compound, 5,932 newly minted
Burned on Arbitrum36,167 rsETH seized from Aave there
rsETH holdersNo cut: 1.0696 ETH per rsETH through the pause

The seized rsETH went back to Kelp. In May a recovery wallet returned it to the lockbox, along with newly minted rsETH paid for with ETH that others chipped in. One payment was 2,000 ETH, the size of the contribution Evercrest says it made. The rsETH seized on Arbitrum was burned there, which shrank the supply the attack had inflated. rsETH holders took no cut. Kelp's exchange rate held through the pause and has risen since.

10 · The claimsThe claims, checked

ClaimWhat the chain shows
Size of the theftEvercrest: 116,500 rsETH, about US$292 million. Verified. 116,500 rsETH at 17:35:35 UTC, $294.6 million at the block's prices.
A fake Unichain messageEvercrest: the verifier was told of a lock on Unichain that never happened. Verified. Unichain had sent 307 messages; the real #308 left 12.6 hours later.
A second attemptEvercrest: about 40,000 more rsETH, stopped. Verified. Exactly 40,000 rsETH; two tries to collect failed on Kelp's freeze.
Kelp acted within an hourEvercrest: detected, paused, froze the wallet. Verified. First freeze after 43 minutes; lockbox frozen by 18:48. 39,743 rsETH had already reached Arbitrum.
Kelp began on defaultsEvercrest: first bridges used LayerZero's defaults. Verified for Arbitrum and Optimism: two verifiers until April 1, 2024.
Kelp cut to one verifierLayerZero: "manually downgraded to a 1/1". Supported. Kelp's own transactions cut 8 routes from 2 verifiers to 1. Evercrest says on LayerZero's advice: can't be checked.
Unichain always 1-of-1Evercrest: the attacked route never had another setting. Verified. One verifier from its first setting in April 2025; LayerZero's default there did not work.
Multi-DVN was advisedLayerZero: its "express recommendation to all integrators". Can't be checked. On chain, 18 of Kelp's 26 routes had no working default.
Others used one verifierEvercrest: 1-of-1 was not unique to Kelp. Verified. 157 apps received LayerZero-only messages into Ethereum, March 1 to April 18.
Almost all 1/1 was rsETHPellegrino: "almost 100% of the volume on a 1/1 [configuration] was rsETH". Partly supported. 83% of value; 2.3% of messages.
Texts approving the setupEvercrest: LayerZero endorsed it in writing. Can't be checked on chain.
Malware, tampered serversBoth sides describe an infrastructure hack. Can't be checked. The verifier signing from its usual wallet fits that account.
A 2,000 ETH contributionEvercrest: paid to restore rsETH's backing. Consistent. 2,000.01 ETH paid into the recovery wallet on May 9; the payer is not named on chain.
Over $650M withdrawnEvercrest: users left after the attack. Consistent. rsETH supply is down 234,810 since the attack.

Each row is a factual claim one side has made in public, next to what the chain shows. The legal questions stay with the court.

11 · The limitsWhat the chain can't tell the court

A blockchain records what people did. It does not record what they were told. The Telegram messages at the centre of Evercrest's case are off-chain, and so are the malware, the tampered nodes and what either side meant. The court also has to decide whether LayerZero owed Kelp a duty of care, and whether its public statements were defamatory. Nothing on chain answers that.

What the chain settles is narrower, and still useful. The first message was fake. The second attempt was real, for exactly 40,000 rsETH, and Kelp stopped it. Kelp's own admin account moved its routes to one verifier. And plenty of other apps ran that way too, though in those seven weeks none moved nearly as much money into Ethereum as rsETH.

12 · How we measuredMethod

Everything here comes from public chain data. We read the bridge contracts on Ethereum. That covers each verifier approval, each delivered message and each change to Kelp's settings, with the defaults as they stood at the time. Unichain's message count comes from Unichain itself. Dollar figures use Kelp's own rsETH exchange rate and market prices of the time. The count of apps on a single verifier covers messages into Ethereum only. The transfers and prices come from Bitquery's contract events and DEX prices. For a smaller bridge hit the same way, see our look at the ASI bridge forgery.

13 · The recordAddresses and transactions

WhatAddress or transaction
rsETH lockbox (bridge)0x85d4…8ef3
rsETH token0xa129…e5a7
LayerZero Labs verifier0x589d…236b
First receiving wallet0x8b1b…0d3b
Collector, both chains0x5d39…7ccc
Frozen ETH, Arbitrum0x3b87…6c07
Recovery wallet0x53cb…53d9
Fake #308 signed0xfe5756…0d6f
116,500 rsETH paid out0x1ae232…4222
Fake #309 signed0xa3e663…36b7
Failed try on #3090x850953…3e53
Arbitrum freeze0x561804…0f6b
Aave write-off0xe2391e…478f
Run it yourself

Check a bridge in plain English

Every figure above came from data anyone can query. The Bitquery MCP server puts it behind an AI assistant, so you can ask which verifiers a bridge route requires, where a wallet sent what it borrowed, or how much left a lockbox in the last hour, without writing the query yourself.

Trace a bridge payout to the wallets that received itFollow borrowed ETH across wallets and chainsWatch a lockbox's balance hour by hourSee which addresses a token contract has frozen
Explore Bitquery MCP →Figures measured September 25, 2026, against Bitquery's Ethereum and Arbitrum data and public Ethereum, Unichain and Arbitrum nodes. Written by Bitquery Research; AI tools ran the queries and drafted the text, and every figure was worked out again from the data before publishing.
Scope, limits and attribution

This article is provided for informational and educational purposes only and reflects analysis of publicly available on-chain data as of the dates indicated. It does not constitute legal, financial, compliance, or investment advice.

It concerns a lawsuit that has not been decided. It takes no position on liability, negligence or defamation, and describes only what public blockchain records show about the facts the parties dispute. Statements by Evercrest, LayerZero and Bryan Pellegrino are quoted from the public sources linked, including Evercrest's filed claim.

Wallets are identified by address only; except where a public statement names them, nothing here states who controls them. The attribution of the attack to any group is LayerZero's, as linked.

Nothing herein should be relied upon as a definitive determination of fact. Readers should conduct their own independent verification before taking any action. The authors and publisher accept no liability for any loss or damage arising from the use of this article.