KelpDAO Sues LayerZero Over $292M Exploit, Alleging Undisclosed Vulnerabilities

Cross-chain lending protocol blames failure to disclose weaknesses for largest hack of 2026

By LineZotpaper
Published
Read Time1 min
KelpDAO, a cross-chain lending protocol, is suing LayerZero and co-founder Brian Pellegrino, accusing them of failing to disclose protocol weaknesses that led to a $292 million exploit — the largest of 2026 so far, according to CoinDesk.

KelpDAO, a cross-chain lending protocol, has filed a lawsuit against LayerZero and its co-founder Brian Pellegrino over the $292 million exploit it describes as the largest of 2026 so far. According to CoinDesk, the lawsuit alleges LayerZero failed to disclose weaknesses in its protocol, which led to the hack. The case targets the interoperability layer rather than the lending application itself, and KelpDAO accuses the defendants of hiding vulnerabilities that were exploited. The report does not include a response from LayerZero or Pellegrino, and no further details of the suit's filing have been released.

§

Analysis

Why This Matters

  • The lawsuit could set a precedent for whether cross-chain infrastructure providers can be held liable for vulnerabilities that enable large-scale exploits.
  • It underscores the legal risks facing DeFi protocols after major hacks and the growing use of litigation to recover stolen funds.

Background

KelpDAO is a cross-chain lending protocol, and LayerZero is an interoperability platform that connects blockchains. The suit centers on whether LayerZero owed a duty to disclose known weaknesses in its software before the exploit occurred. The case is among the largest of 2026 in the crypto sector.

Key Perspectives

KelpDAO: Alleges LayerZero and Brian Pellegrino failed to disclose protocol weaknesses, directly enabling the $292 million exploit. LayerZero and Brian Pellegrino: No response or counter-perspective is included in the available report; their defense is not yet known. Critics/Skeptics: Questions may be raised about whether responsibility rests primarily with the lending protocol that integrated the interoperability layer, though no such arguments are detailed in the source.

What to Watch

  • Whether LayerZero files a motion to dismiss or countersues, and what arguments it mounts regarding disclosure obligations.
  • Whether other protocols affected by similar exploits pursue legal action against infrastructure providers.
  • Any settlement or court ruling that could clarify liability in cross-chain DeFi incidents.

Sources

Zotpaper

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.