What happened: the $292M rsETH bridge loss
KelpDAO, a liquid staking protocol, suffered a substantial loss through its rsETH bridge integration in late 2025. The exact mechanics of the exploit have not been fully disclosed in public court filings, but the core allegation is straightforward: a vulnerability in the bridge architecture allowed attackers to extract approximately $292 million in user funds. KelpDAO's legal claim centers on a specific assertion: LayerZero, the cross-chain messaging protocol that underpins many bridges, had reviewed and endorsed the bridge setup before the attack occurred. According to KelpDAO's complaint, this pre-attack endorsement creates liability if the endorsed architecture contained exploitable flaws.
LayerZero CEO Bryan Pellegrino has publicly characterized the lawsuit as meritless, suggesting that the protocol did not provide the kind of security guarantee KelpDAO alleges. This disagreement over what was promised versus what was delivered is the crux of the dispute. Bridge exploits themselves are not uncommon in crypto; what makes this case notable is that the victim is pursuing legal recourse against the underlying infrastructure provider, not just the attacker.
How bridge protocols work and why they fail
Cross-chain bridges allow users to move crypto assets from one blockchain to another by locking them on the source chain and minting wrapped versions on the destination chain. LayerZero is a message-passing protocol designed to facilitate this kind of interoperability, but it does not directly custody the funds; projects like KelpDAO build their own bridge contracts on top of LayerZero's infrastructure. The bridge contract must correctly implement the logic that matches locked assets to minted tokens, verify signatures, and prevent double-spending.
Vulnerabilities typically emerge at the contract level, not the protocol level. A bridge might miscalculate collateral, accept forged verification, or fail to atomically lock and mint. The attack surface is large because bridge code must handle edge cases across two or more chains simultaneously. KelpDAO's claim is not that LayerZero's core protocol is flawed, but that LayerZero provided endorsement of a specific bridge implementation that turned out to be insecure. This is a critical distinction: the lawsuit is not about LayerZero's code having a bug, but about whether LayerZero took responsibility for vetting a third party's use of that code.
The liability question: who is responsible for what
This lawsuit sits in a gray zone of crypto law and contract interpretation. LayerZero is an infrastructure provider; KelpDAO is the project that deployed the actual bridge. In traditional software, vendors typically disclaim responsibility for how third parties use their APIs, but they may accept limited liability if they explicitly audit or endorse a specific implementation. The distinction matters legally. If LayerZero said "we have reviewed this bridge and it is secure," the company may have accepted a duty of care. If LayerZero said "we provide message-passing; you are responsible for your own bridge contract," the company likely bears no liability.
KelpDAO's argument appears to rest on the first interpretation: that LayerZero's pre-attack endorsement converted what would otherwise be a routine smart-contract audit into a contractual representation of security. Pellegrino's dismissal suggests LayerZero is arguing the opposite: that no such endorsement was binding or even occurred in the form KelpDAO describes. The court will have to examine what LayerZero actually said, in what context, and whether it was specific enough to constitute a legal duty.
Why this matters for bridge users and projects
If KelpDAO prevails, the precedent would signal that infrastructure providers can incur liability for endorsing third-party implementations, even after performing standard audits. This could reshape how protocols like LayerZero operate. Projects might become more cautious about publicly supporting bridges, or they might require stronger disclaimers and insurance. Conversely, if LayerZero wins, bridge operators will continue to shoulder full responsibility for their own security, and infrastructure providers will face no liability for vetting external implementations.
For ordinary bridge users, the immediate lesson is that brand affiliation and endorsement do not always mean financial protection. A bridge that integrates LayerZero, has a public audit, or receives commentary from a major protocol can still lose user funds. This suit does not change that reality, but it may eventually clarify whether victims have recourse beyond reporting the attack.
How crypto bridge exploits historically played out
The bridge sector has been hit by repeated large-scale exploits over the past several years. Ronin, Poly Network, and Nomad all suffered nine-figure losses from bridge vulnerabilities, and in most cases the affected projects bore the loss themselves or forked their blockchains to reverse the damage. Rarely have bridge exploits resulted in settlements or legal recoveries. This lawsuit is unusual because it targets the infrastructure layer rather than the bridge operator's own negligence. It is also unusual because the dollar amount and the reputational stakes for LayerZero are high enough to justify expensive legal defense.
The historical pattern shows that bridge design is genuinely hard and that endorsements or audits do not eliminate risk. The Ronin bridge, which was exploited for $625 million in 2022, had been reviewed by reputable security firms. This suggests that either the scope of audits was insufficient, or that new attack vectors emerge after deployment. Either way, the lesson is that bridges are high-risk infrastructure, and no endorsement by a protocol layer erases that risk.
Current status and what to watch
As of late 2025, KelpDAO's lawsuit is ongoing, and the ultimate outcome is uncertain. Both sides have made their positions clear: KelpDAO maintains that LayerZero endorsed a flawed bridge, while LayerZero and Pellegrino deny that any such binding endorsement was provided. The case will likely hinge on documentary evidence: emails, audit reports, public statements, and the terms of any formal agreement between the two projects.
Watch for how the court handles the question of whether audit or endorsement creates contractual liability in crypto. This could influence how infrastructure projects approach third-party integrations and what language they use when commenting on external implementations. It may also prompt other bridge victims to pursue similar claims against underlying infrastructure providers.
Key takeaways: understanding infrastructure risk in bridges
The rsETH exploit and resulting lawsuit highlight three practical realities. First, a bridge's connection to a reputable protocol layer does not guarantee security; infrastructure endorsement is not the same as insured protection. Second, legal recourse in crypto is slow, uncertain, and ultimately depends on factors (jurisdiction, contract language, regulatory status) that ordinary users cannot fully control. Third, the risk of bridge exploits persists regardless of industry growth or market confidence, because the technical challenge of secure cross-chain design remains unsolved.
If you use bridges to move assets across chains, treat each bridge as a distinct security boundary, not as an extension of the source blockchain's security model. Check whether the bridge operator has obtained liability insurance or offered a recovery fund. Verify the audit reports yourself rather than relying on third-party endorsements. Move only the amount you can afford to lose, and be prepared for the possibility that an exploit could occur even with prominent backing.
Source: Cointelegraph
