What caught my attention with the KelpDAO story is not just the $294M exploit.

It is what happened after the funds disappeared.

Evercrest Technologies has now filed a lawsuit against LayerZero over the April exploit. KelpDAO alleges that LayerZero failed to disclose weaknesses and risks in its technology and also claims the infrastructure had already been reviewed before the deployment.

LayerZero co founder Bryan Pellegrino has described the lawsuit as meritless and said he is prepared to defend himself in court.

So the legal claims are still allegations rather than established facts.

But the technical failure itself shows why cross chain infrastructure remains such an important risk point in DeFi.

The attacker managed to exploit the messaging system and caused around 116600 rsETH to be minted. Those tokens were then used as collateral to obtain around 106467 ETH.

That is where the damage becomes much bigger than the original token creation.

The response has also been interesting.

The Arbitrum Security Council froze around 30766 ETH linked to the exploit which helped prevent those assets from moving further.

KelpDAO later replenished its rsETH adapter with around 116000 rsETH and resumed normal operations.

The protocol also moved its cross chain communication layer to Chainlink CCIP.

KelpDAO says its rsETH is now backed 1 to 1 by ETH and reported around 426819 ETH in actual backing.

The recovery is visible in the TVL too.

Kelp added around $266M in TVL from August 19 to reach roughly $1.139B.

But there is still a gap.

That remains below the roughly $1.547B TVL recorded in May.

And earnings have weakened sharply with quarterly earnings around $276K while gross revenue stood near $6.42M.

For me this makes the lawsuit less interesting than the infrastructure lesson behind it.

A DeFi protocol can replenish stolen assets and change its messaging system.

But users still need to trust the new security assumptions.

The real test for KelpDAO is therefore not simply whether TVL comes back.

It is whether the protocol can rebuild capital while proving that the architecture behind that capital has become harder to compromise.

The exploit is over.

The trust question is not.