policyvia The Block

KelpDAO Sues LayerZero, Claims Bridge Setup Endorsed in $292M Exploit

KelpDAO is suing LayerZero and its CEO, claiming the bridge protocol endorsed a risky setup that led to a $292 million exploit in April. The lawsuit highlights ongoing concerns about bridge security in DeFi.

Key takeaways

  • KelpDAO is suing LayerZero and CEO Bryan Pellegrino over a $292 million exploit in April.
  • The lawsuit alleges LayerZero endorsed a risky single-verifier configuration in writing.
  • The exploit targeted rsETH on the KelpDAO protocol, draining $292 million.
  • Chainlink updated its bridge tech with custom security checks after the exploit.
  • Kraken and Lombard moved billions from LayerZero to Chainlink after the hack.
KelpDAO Sues LayerZero, Claims Bridge Setup Endorsed in $292M Exploit

KelpDAO, a cross-chain lending protocol, has filed a lawsuit against LayerZero and its CEO, Bryan Pellegrino, over the $292 million exploit that occurred on April 18. The lawsuit alleges that LayerZero endorsed a single-verifier configuration in writing, which was later exploited. KelpDAO claims this endorsement made LayerZero liable for the damages incurred.

What Happened in the Exploit?

The exploit targeted rsETH, a wrapped version of Ethereum's restaked ETH, on the KelpDAO protocol. The attackers exploited a vulnerability in the bridge setup, which allowed them to drain $292 million. The lawsuit claims that LayerZero had approved this setup in writing, despite later warning other projects about the risks of single-verifier configurations.

Why the Timing Matters

The lawsuit comes months after the exploit, as the DeFi community continues to grapple with the security risks of cross-chain bridges. Chainlink, another bridge protocol, has recently updated its software to include custom security checks, aiming to prevent similar exploits. This move highlights the industry's response to the growing concerns around bridge security.

What It Means for DeFi Users

For DeFi users, this lawsuit underscores the importance of due diligence when using cross-chain bridges. The exploit and subsequent legal action serve as a reminder that even protocols with established reputations can be vulnerable. Users should look for protocols that implement robust security measures, such as multi-verifier configurations and regular audits.

Additionally, this case may set a precedent for future legal actions in the DeFi space. If KelpDAO succeeds in holding LayerZero liable, it could encourage other victims of exploits to pursue legal recourse against bridge protocols.

Frequently asked questions

What was the $292 million exploit on KelpDAO?

The exploit targeted rsETH on the KelpDAO protocol, exploiting a vulnerability in the bridge setup to drain $292 million.

Why is KelpDAO suing LayerZero?

KelpDAO claims LayerZero endorsed a risky single-verifier configuration in writing, making it liable for the damages incurred in the exploit.

What is Chainlink doing to prevent similar exploits?

Chainlink updated its bridge technology to include custom security checks, aiming to prevent similar single-point-of-failure vulnerabilities.

What should DeFi users look for in bridge protocols?

DeFi users should look for protocols that implement robust security measures, such as multi-verifier configurations and regular audits.