[An $292 million hacker incident ends up in court! Who should be held responsible: KelpDAO or LayerZero?🔥]

🚀 币圈安全事件,进群聊

This year’s biggest DeFi attack in the crypto market has now seen new developments.

KelpDAO has officially sued the cross-chain protocol LayerZero, seeking to assign responsibility for the approximately $292 million attack that occurred in April.

At the time, the attacker stole 116,500 rsETH from KelpDAO’s cross-chain bridge, which then triggered a chain reaction—multiple DeFi protocols paused trading and borrowing of the affected assets, and the DeFi market even faced a liquidity crisis for a time.

The question is: whose problem is it, really?

KelpDAO believes LayerZero failed to adequately disclose the risks of its own technology. Moreover, after LayerZero-related infrastructure was compromised, the forged cross-chain messages were ultimately validated and passed through.

But LayerZero tells a completely different story.

LayerZero previously said that KelpDAO used a “single-validator” configuration—meaning it relied on only one validation path. If that validator is compromised, it could become a single point of failure for the entire cross-chain bridge.

So now the dispute has shifted from “whose technology went wrong” to “who should be responsible for the $292 million loss.”

📌 What truly deserves attention here isn’t just the $292 million loss, but the security of cross-chain bridges: when a DeFi protocol moves assets across different chains, any issue in the underlying validation mechanism, infrastructure, or permission configuration can amplify technical risk into massive financial losses.

And how this lawsuit ultimately rules may also become an important precedent for how future DeFi projects handle accountability for cross-chain security.
#KelpDAO