Coindesk KelpDAO Sues LayerZero Over $292M Exploit in Cross-Chain Protocol
Article Content
- •KelpDAO accuses LayerZero of failing to disclose vulnerabilities leading to a $292M exploit.
- •The exploit involved social engineering to compromise a developer account and exploit a verifier vulnerability.
- •The incident triggered a liquidity crisis in DeFi, erasing $20 billion in deposits.
KelpDAO has initiated a lawsuit against LayerZero and its CEO Bryan Pellegrino, claiming that undisclosed vulnerabilities in LayerZero's cross-chain protocol led to a $292 million exploit. The attack, which occurred on April 22, involved social engineering tactics to compromise a developer account, allowing attackers to exploit a single verifier vulnerability and drain 116,500 rsETH. This incident not only resulted in significant financial losses for KelpDAO but also triggered a liquidity crisis that erased $20 billion in decentralized finance deposits. Pellegrino has labeled the lawsuit as meritless and plans to defend himself in a British Columbia court. The legal dispute raises questions about the security of cross-chain infrastructure and its implications for future regulatory scrutiny in the crypto sector.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Bryan Pellegrino in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in F5 BIG-IP APM Exploited for Remote Code Execution F5 Networks has reported a critical vulnerability in its BIG-IP Access Policy Manager (APM), tracked as CVE-2026-94127, which is being actively exploited in the wild. The flaw allows unauthenticated attackers to execute remote code on systems configured with both an APM access policy and an OAuth profile. This…
Massive Network of AI Proxy Servers Used for Malicious Activities Uncovered Security researchers from Team Cymru have identified over 10,000 proxy servers in China facilitating malicious AI activities. These servers, termed 'transfer stations,' are primarily used to bypass geographic restrictions and conduct model distillation attacks against frontier AI models. The infrastructure allows…