policyvia Decrypt

KelpDAO Developer Sues LayerZero Over $292M Bridge Exploit

Evercrest, a developer for the KelpDAO cross-chain lending protocol, is suing LayerZero for $292 million in damages. The lawsuit claims LayerZero approved a risky single-verifier configuration in writing multiple times, then warned a different developer about the same vulnerability. This is the largest crypto exploit of 2026 so far.

Key takeaways

  • Evercrest is suing LayerZero and co-founder Brian Pellegrino for $292 million.
  • LayerZero allegedly approved a risky single-verifier configuration in writing multiple times.
  • LayerZero warned other developers about the vulnerability but not KelpDAO.
  • This is the largest crypto exploit of 2026 so far.
  • The lawsuit could set a precedent for cross-chain bridge security disclosures.
KelpDAO Developer Sues LayerZero Over $292M Bridge Exploit

Evercrest, a developer for the KelpDAO cross-chain lending protocol, has filed a lawsuit against LayerZero and its co-founder Brian Pellegrino, seeking $292 million in damages. The lawsuit alleges that LayerZero approved a single-verifier configuration for KelpDAO's bridge multiple times in writing, then later warned other developers about the same configuration's risks without notifying KelpDAO. This exploit is the largest crypto hack of 2026 so far.

What Led to the Lawsuit?

The lawsuit claims that LayerZero approved the single-verifier configuration for KelpDAO's bridge, which was later exploited. Evercrest alleges that LayerZero knew about the risks associated with this configuration but failed to disclose them to KelpDAO. Instead, LayerZero warned other developers about the same risks, according to the lawsuit. CoinDesk reports that the complaint specifically accuses LayerZero and Pellegrino of failing to disclose weaknesses in their protocol, which directly led to the $292 million hack.

Why This Matters for Crypto Users

This lawsuit highlights the risks associated with cross-chain bridges, which have been a common target for hackers. The exploit is part of a broader pattern of security issues in the crypto space, particularly with cross-chain bridges. For example, Taiko paused its Ethereum Layer-2 network after a $1.7M bridge exploit, and Lombard moved $4B to Chainlink after a LayerZero exploit.

What's Next for KelpDAO and LayerZero?

The lawsuit is ongoing, and the outcome could set a precedent for how cross-chain bridge developers handle security risks. If Evercrest wins, it could lead to stricter regulations and better disclosure practices in the crypto industry. Users of cross-chain bridges should be cautious and monitor the developments in this case closely.

Frequently asked questions

What is a single-verifier configuration?

A single-verifier configuration is a setup where one entity verifies transactions on a cross-chain bridge. This centralizes control and makes the bridge more vulnerable to exploits.

How common are cross-chain bridge exploits?

Cross-chain bridge exploits are relatively common in crypto. They have been frequent targets for hackers due to the large amounts of funds they hold and the complexity of their security setups.

What could the outcome of this lawsuit mean for the crypto industry?

The outcome could set a precedent for how cross-chain bridge developers handle security risks. It might lead to stricter regulations and better disclosure practices in the industry.

How can users protect themselves from cross-chain bridge exploits?

Users should be cautious when using cross-chain bridges and monitor developments in security practices. Keeping funds in more secure wallets and diversifying assets can also help mitigate risks.