Kelp DAO v. LayerZero: what the blockchain shows
One forged message emptied a bridge in April. Now the firm behind the bridge is suing the firm whose software approved it, and much of what they dispute sits on public blockchains, where anyone can check it.
- 12.6 hours
- 40,000
- 8 routes
- 18 of 26
- 157 apps
- 30,766 ETH
01 · The payoutA transfer that never happened
On the evening of Saturday, April 18, 2026, a new wallet on Ethereum received 116,500 rsETH. It had been funded that morning with a small amount from Tornado Cash, the mixer. The tokens came out of Kelp DAO's bridge contract. It released them because it had been told the same amount was on its way in from Unichain.
Nothing had left Unichain. Within minutes the rsETH sat in seven wallets. Within two hours the attacker had turned it into about 106,000 ETH, mostly by borrowing against it on Aave, Compound and Euler. At the time it was, in CoinDesk's words, "2026's biggest crypto exploit".
02 · The piecesKelp, rsETH and the verifier
Kelp DAO issues rsETH, a liquid restaking token. You deposit ETH with Kelp and get rsETH back. Kelp stakes and restakes the ETH to earn rewards, and rsETH keeps earning them while you trade it, bridge it or borrow against it. Before the attack there was some $1.6 billion of it.
rsETH lives on Ethereum but is used on 26 other networks. To move it between them, Kelp used LayerZero, a cross-chain messaging protocol that many token teams use as a bridge. When rsETH leaves Ethereum, it is locked in Kelp's bridge contract, the lockbox, and the same amount is minted on the other chain. On the way back the copy is burned and the lockbox releases the original. So the lockbox holds the backing for every rsETH outside Ethereum.
Each of those moves is a message, say, "10 rsETH locked on Unichain, release 10 on Ethereum." Before Ethereum acts on it, at least one verifier has to confirm the lock really happened. Each is called a DVN, short for decentralized verifier network, and every app picks its own. An app can require several, or just one. With one, a single approval releases the funds.
Kelp DAO is built by Evercrest Technologies, a Panama company. LayerZero Labs, based in Vancouver, builds the protocol and runs one verifier.
03 · The lawsuitEvercrest v. LayerZero
On September 24, Evercrest sued LayerZero Labs, its Canadian arm and Bryan Pellegrino, its co-founder and chief executive, in the Supreme Court of British Columbia, as The Crypto Times reported. The claim says the hack was of LayerZero's own systems, and that the company had reviewed and approved Kelp's setup with a single verifier. Then, it says, the company and Pellegrino put the fault on Kelp in public. Evercrest wants damages for negligent misrepresentation, negligence and defamation. None of it has been tested in court.
LayerZero sees it differently. Its incident statement says Kelp's route "relied on a 1-of-1 DVN setup, with LayerZero Labs as the sole verifier", and that more than one verifier is "LayerZero's express recommendation to all integrators". It told CoinDesk that Kelp "deployed multiDVN and then manually downgraded to a 1/1."
A lot of this happened on public chains, so it can be checked. We rebuilt the attack from the Ethereum, Unichain and Arbitrum records, along with every change Kelp made to its bridge settings since early 2024. Evercrest's account of the attack holds up in detail. So does LayerZero's point about the downgrade, on the routes that had a working default. One of Pellegrino's public claims holds only in part. What was said in private, and who is liable, is for the court.
04 · The forgeryHow one approval released $295 million
Every message on a route carries a nonce, a number that goes up by one each time. The message that emptied the lockbox claimed to be number 308 from Kelp's rsETH contract on Unichain. Two minutes before the payout, LayerZero Labs' verifier approved it. The attacker's own wallet then submitted it on Ethereum and collected.
Unichain says otherwise. Its end of the bridge counts every message it sends, and at the moment of the payout that count stood at 307. Six hours later it still did. The real message 308 left Unichain the next morning, more than 12 hours after the payout, carrying a couple of dollars' worth of rsETH. It never arrived. Its slot on Ethereum was already taken.
The fake approval came from the same wallet that sends the verifier's routine ones, before and after the attack. That fits LayerZero's own incident report. It says the attacker fed the verifier false data through the nodes it used to read other chains. Then the attacker knocked out the outside nodes it could have used instead. The report also says a North Korean group, which it calls TraderTraitor, was behind the attack. None of that shows up on-chain.
What does show up is Kelp's setting for the route, read from Ethereum just before the attack: one verifier, LayerZero Labs, and no backup. One approval was all it took.
05 · The second try40,000 more, 50 minutes later
The first payout left the lockbox almost empty. Then the attacker did an odd thing. It sent about a third of the rsETH back out of Ethereum, to Arbitrum. Every rsETH that leaves Ethereum gets locked in that same lockbox, so the attacker was filling it back up. With other users' bridging, it soon held just over 40,000 rsETH.
Fifty minutes after the first payout, the same verifier approved a second message from Unichain, number 309. Ethereum stores only a hash of each message, a fingerprint of its contents, so we tried amounts until one matched. It was exactly 40,000 rsETH, to the same wallet as before. The attacker's two failed attempts to collect it show the same amount. Kelp had frozen that wallet in the rsETH contract three minutes before.
Evercrest's claim says Kelp stopped a second theft of "approximately 40,000 rsETH". The record matches, to the token. Kelp's first freeze came about 43 minutes after the payout. Minutes later it paused rsETH, and within half an hour it froze the lockbox itself.
It was not fast enough for everything. The rsETH sent to Arbitrum had already landed there before Kelp's first freeze.
06 · The settingWho chose one verifier, and when
Most of the lawsuit is about what came before the attack. How did Kelp's routes end up relying on a single verifier? Every change to a route's verifier list is an on-chain transaction. That let us read the whole history: Kelp's setting on each of its 26 routes into Ethereum, and the default when Kelp first set it.
Kelp's first route, from Arbitrum, went live in February 2024 on LayerZero's default. That meant two verifiers, LayerZero Labs and Google Cloud, and its first 151 messages carry both approvals. Then, on April 1 that year, the admin account on Kelp's bridge switched the Arbitrum and Optimism routes to LayerZero Labs alone. From then on one approval was enough. In all, the default used two verifiers on eight of Kelp's routes, and Kelp's own transactions cut each to one.
That part matches LayerZero's line that Kelp "manually downgraded". Evercrest's claim says Kelp made those changes on the company's advice, in written messages the chain cannot show. One date does line up. The claim says that on March 21, 2024, LayerZero told Kelp to use one verifier on routes that had no default. Early that morning, Kelp moved its Mode and Blast routes from two verifiers to one.
The route that was attacked is a different case. On 18 of Kelp's 26 routes, Unichain among them, there was no working default at all. On Unichain the default verifier was a placeholder that rejects every message with the words "Please set your OApp's DVNs and/or Executor". Kelp had to choose. In April 2025 it opened the Unichain route with LayerZero Labs alone. The route never had another setting until after the attack, just as the claim says.
By the day of the attack, all but two of Kelp's routes into Ethereum ran on one verifier. Five days later Kelp moved every route to four.
07 · How commonWas Kelp alone?
Whether that setup was rare has become its own fight. In May, Pellegrino wrote that "almost 100% of the volume on a 1/1 [configuration] was rsETH", as quoted in Evercrest's claim. Kelp's own memo, as CoinDesk reported, put the share of active apps with one verifier at close to half.
So we counted. In the seven weeks before the attack, some 7,000 messages arrived on Ethereum with an approval from LayerZero Labs alone. They went to 157 apps. We checked the settings of the busiest 15, and every one used that verifier and nothing else, just like Kelp. By number of messages, rsETH was one app among many, with 2.3% of them.
By value it was far ahead. The tokens in those messages were worth $106.5 million, and rsETH was 83% of it. The next largest apps moved a few million dollars each. By value, Pellegrino's point holds. By count, the record does not support it. rsETH carried most of the value that relied on one verifier, but plenty of other apps relied on it too.
08 · The moneyWhere the 116,500 rsETH went
Back to April 18. The attacker sold little of the rsETH and borrowed against the rest. The biggest share went into Aave on Ethereum, with more in Compound and Euler. A smaller part was sold outright. The rest was bridged to Arbitrum and posted on Aave there. All told, the attacker raised about 106,000 ETH and gathered it in one address, 0x5d39…7ccc, on both chains.
On Arbitrum the money never left. Early on April 21, 30,766 ETH moved out of that address in a transaction the attacker did not sign. Arbitrum's Security Council said it had frozen the funds, as CoinDesk reported. In June the ETH moved again, to a multisig on Arbitrum, where it still sits.
On Ethereum the attacker waited two and a half days. Then it split about 75,700 ETH across more than a hundred new wallets. From there it swapped the ETH for Bitcoin through THORChain, a protocol that trades coins across chains. About 71,200 ETH went that way once refunds are netted out, most of it within a day and a half, to 351 Bitcoin addresses. Smaller sums went out through other bridges and stablecoins. Scammers, meanwhile, dropped fake "ETH" tokens into look-alike wallets at every step, which makes the trail harder to follow by eye. We counted only real ETH.
09 · The billWho paid
Someone had to cover the hole. The lenders went first. In May, Aave wrote off about 83,000 WETH across Ethereum and Arbitrum and seized the attacker's rsETH collateral for almost nothing. What the attack did to Aave's depositors is its own story, told in The week $12 billion left Aave. Compound was paid for the rsETH stuck in its markets, with WETH from a wallet funded partly by Aave's treasury.
| Who | What it paid or got back |
|---|---|
| Aave, Ethereum | 52,964 WETH written off, May 6 |
| Aave, Arbitrum | 29,835 WETH and 821 wstETH written off, May 6 |
| Compound | Paid 16,782 WETH for 17,426 rsETH, May 9 |
| Into the recovery wallet | 2,000 ETH and 5,000 ETH on May 9; 143 ETH from Euler's multisig |
| Back to the lockbox | 76,758 rsETH in May: 53,400 from Aave, 17,426 from Compound, 5,932 newly minted |
| Burned on Arbitrum | 36,167 rsETH seized from Aave there |
| rsETH holders | No cut: 1.0696 ETH per rsETH through the pause |
The seized rsETH went back to Kelp. In May a recovery wallet returned it to the lockbox, along with newly minted rsETH paid for with ETH that others chipped in. One payment was 2,000 ETH, the size of the contribution Evercrest says it made. The rsETH seized on Arbitrum was burned there, which shrank the supply the attack had inflated. rsETH holders took no cut. Kelp's exchange rate held through the pause and has risen since.
10 · The claimsThe claims, checked
| Claim | What the chain shows |
|---|---|
| Size of the theft | Evercrest: 116,500 rsETH, about US$292 million. Verified. 116,500 rsETH at 17:35:35 UTC, $294.6 million at the block's prices. |
| A fake Unichain message | Evercrest: the verifier was told of a lock on Unichain that never happened. Verified. Unichain had sent 307 messages; the real #308 left 12.6 hours later. |
| A second attempt | Evercrest: about 40,000 more rsETH, stopped. Verified. Exactly 40,000 rsETH; two tries to collect failed on Kelp's freeze. |
| Kelp acted within an hour | Evercrest: detected, paused, froze the wallet. Verified. First freeze after 43 minutes; lockbox frozen by 18:48. 39,743 rsETH had already reached Arbitrum. |
| Kelp began on defaults | Evercrest: first bridges used LayerZero's defaults. Verified for Arbitrum and Optimism: two verifiers until April 1, 2024. |
| Kelp cut to one verifier | LayerZero: "manually downgraded to a 1/1". Supported. Kelp's own transactions cut 8 routes from 2 verifiers to 1. Evercrest says on LayerZero's advice: can't be checked. |
| Unichain always 1-of-1 | Evercrest: the attacked route never had another setting. Verified. One verifier from its first setting in April 2025; LayerZero's default there did not work. |
| Multi-DVN was advised | LayerZero: its "express recommendation to all integrators". Can't be checked. On chain, 18 of Kelp's 26 routes had no working default. |
| Others used one verifier | Evercrest: 1-of-1 was not unique to Kelp. Verified. 157 apps received LayerZero-only messages into Ethereum, March 1 to April 18. |
| Almost all 1/1 was rsETH | Pellegrino: "almost 100% of the volume on a 1/1 [configuration] was rsETH". Partly supported. 83% of value; 2.3% of messages. |
| Texts approving the setup | Evercrest: LayerZero endorsed it in writing. Can't be checked on chain. |
| Malware, tampered servers | Both sides describe an infrastructure hack. Can't be checked. The verifier signing from its usual wallet fits that account. |
| A 2,000 ETH contribution | Evercrest: paid to restore rsETH's backing. Consistent. 2,000.01 ETH paid into the recovery wallet on May 9; the payer is not named on chain. |
| Over $650M withdrawn | Evercrest: users left after the attack. Consistent. rsETH supply is down 234,810 since the attack. |
Each row is a factual claim one side has made in public, next to what the chain shows. The legal questions stay with the court.
11 · The limitsWhat the chain can't tell the court
A blockchain records what people did. It does not record what they were told. The Telegram messages at the centre of Evercrest's case are off-chain, and so are the malware, the tampered nodes and what either side meant. The court also has to decide whether LayerZero owed Kelp a duty of care, and whether its public statements were defamatory. Nothing on chain answers that.
What the chain settles is narrower, and still useful. The first message was fake. The second attempt was real, for exactly 40,000 rsETH, and Kelp stopped it. Kelp's own admin account moved its routes to one verifier. And plenty of other apps ran that way too, though in those seven weeks none moved nearly as much money into Ethereum as rsETH.
12 · How we measuredMethod
Everything here comes from public chain data. We read the bridge contracts on Ethereum. That covers each verifier approval, each delivered message and each change to Kelp's settings, with the defaults as they stood at the time. Unichain's message count comes from Unichain itself. Dollar figures use Kelp's own rsETH exchange rate and market prices of the time. The count of apps on a single verifier covers messages into Ethereum only. The transfers and prices come from Bitquery's contract events and DEX prices. For a smaller bridge hit the same way, see our look at the ASI bridge forgery.
13 · The recordAddresses and transactions
| What | Address or transaction |
|---|---|
| rsETH lockbox (bridge) | 0x85d4…8ef3 |
| rsETH token | 0xa129…e5a7 |
| LayerZero Labs verifier | 0x589d…236b |
| First receiving wallet | 0x8b1b…0d3b |
| Collector, both chains | 0x5d39…7ccc |
| Frozen ETH, Arbitrum | 0x3b87…6c07 |
| Recovery wallet | 0x53cb…53d9 |
| Fake #308 signed | 0xfe5756…0d6f |
| 116,500 rsETH paid out | 0x1ae232…4222 |
| Fake #309 signed | 0xa3e663…36b7 |
| Failed try on #309 | 0x850953…3e53 |
| Arbitrum freeze | 0x561804…0f6b |
| Aave write-off | 0xe2391e…478f |
Check a bridge in plain English
Every figure above came from data anyone can query. The Bitquery MCP server puts it behind an AI assistant, so you can ask which verifiers a bridge route requires, where a wallet sent what it borrowed, or how much left a lockbox in the last hour, without writing the query yourself.
This article is provided for informational and educational purposes only and reflects analysis of publicly available on-chain data as of the dates indicated. It does not constitute legal, financial, compliance, or investment advice.
It concerns a lawsuit that has not been decided. It takes no position on liability, negligence or defamation, and describes only what public blockchain records show about the facts the parties dispute. Statements by Evercrest, LayerZero and Bryan Pellegrino are quoted from the public sources linked, including Evercrest's filed claim.
Wallets are identified by address only; except where a public statement names them, nothing here states who controls them. The attribution of the attack to any group is LayerZero's, as linked.
Nothing herein should be relied upon as a definitive determination of fact. Readers should conduct their own independent verification before taking any action. The authors and publisher accept no liability for any loss or damage arising from the use of this article.