KelpDAO has lawyered up: it's suing cross-chain protocol LayerZero and co-founder/CEO Bryan Pellegrino over the April raid on its rsETH bridge that drained 116,500 tokens worth roughly $292 million — allegedly by North Korean hackers who walked straight into LayerZero's own node infrastructure. Nothing says 'we fixed it' quite like a court date.
▪️ [Mechanism] Attackers got inside LayerZero's internal nodes and pushed a forged cross-chain message through its verifier. That's it — that's the whole heist.
▪️ [Mechanism] It worked because Kelp's bridge ran exactly one verification path: a single LayerZero DVN deciding whether millions walked out the door. One verifier, one signature, one place to hit.
▪️ [Mechanism] With no second independent verifier required, the bridge released the rsETH the moment LZ's verifier approved the fake message. Single point of failure, fully load-bearing, zero backup.
▪️ [Layer Zero side] LZ's own incident report admits it had recommended stacking multiple DVNs — and only after the hit did LZ stop being anyone's sole required verifier.
▪️ [Kelp side] Kelp claims LZ reviewed its deployment configuration before launch and confirmed it secure — then spent months publicly blaming Kelp instead.
▪️ [Fallout] The aftershock forced Aave into an emergency borrow of $300 million just to feed withdrawal demand while DeFi bled deposits market-wide.
📊 Circulating supply parked on the bridge at attack time:
≈⅕@grabway_chat