OpenAI and Anthropic CEOs summoned to appear at Australian AI inquiry hearing
Ethereum Bulls Are Closing In on a Major Breakout: Is This Resistance the Final Barrier?
‘Crypto Mom’ Hester Peirce Resigns From SEC Effective Oct 2
Capital B CEO: Bitcoin Is the Only Asset the U.S. Government Is Unwilling to SellCapital B CEO...
15 Institutions Spoke to Bitwise: More Crypto Buyers May Be Coming
A whale holds a 550,000 SOL long position for a month and a half, currently with an unrealized profit of $22.43 million
Grayscale Files for Zcash Income ETF With Planned Biweekly Payouts
THORChain responds to criticism over "handling hacker funds": a decentralized, permissionless protocol cannot refuse
OKX Founder Criticizes THORChain's Decentralization Claims
Slow Fog's Yuxian Critiques THORChain's Response to Security Incidents
Beijing police crack cross-border telecom fraud case, impersonating police to induce international students to transfer funds and exchange for USDT, freezing 780,000 yuan in involved funds
ETH breaks above $2,700, up 0.28% intraday
THORChain Addresses Security Concerns Following Bitget Incident
Ethereum Whale Realizes $72.83 Million Profit from Recent Sales
XRP Community Takes Center Stage in Evernorth’s Nasdaq Plans
An ETH whale took profit on about 30,000 ETH 9 hours ago, selling 112,000 ETH in a week for a $72.83 million profit
Whale 0xd0A4 withdrew 18.34M $ENA($5.13M) from #Gate, #Bybit, #OKX and #Binance...
AMLBot Traces About 4 BTC From Bitget Hack Into Wasabi CoinJoinCrypto compliance and blockchain...
Pump Fun Liquidates 47,994 SOL for $6 Million, Total Sales Exceed $848 Million
Pump fun(@Pumpfun) sold another 47,994 $SOL ($5.83M) 2 hours ago.In total, pump.fun has sold...
Bitcoin up 43.5% in Q3 as Ethereum surges 71%, supported by ETF demand and spot buyingRead...
ZEC hits all-time high, peaking at $1,697.45
193,627,000 $USDC (193,578,593 USD) transferred from Unknown Whale 1 to #Aave...
Bitcoin Price Gains 44% for Second-Best Q3 as Ethereum Jumps 71%
KLEA Crypto Daily: Saturday, September 26, 2026
Coinbase CEO Stands by His $400K Bitcoin Prediction for 2030Coinbase CEO Brian Armstrong...
193,627,346 $USDC (193,650,581 USD) transferred from #Aave to Unknown Whale 1...
GoPlus: Bitget’s $387.5M Hack Exploited the Transaction-Signing Trust Chain, Not Private KeysGoPlus...
OKX founder and CEO Star Xu said THORChain’s TSS vaults are collectively controlled by validators,...
THORChain responded to Bitget CEO Gracy Chen’s request that it refuse transactions from publicly...
Robert Kiyosaki Names 3 Income Types That Separate Rich and Poor
1,256 $BTC (105,882,575 USD) transferred from unknown wallet to unknown wallet...
Researchers Propose Zcash-Style Privacy for Bitcoin Without a Soft Fork
Solana’s Alpenglow Hits Second Testnet, 100ms Finality in Sight
River Exchange Initiates $6.7 Million Lawsuit Against Canadian Bitcoin Miner
SEC clears regulatory hurdle as crypto token buybacks hit record $638 million
Bitget CEO Wants Thorchain to Block Hackers, but There’s a Catch
Top Trending Coins (Today) 1. ASTRO 2. EDEL 3. TRUMP 4. QNT 5. NEAR 6. SUI 7. HYPE 8. ONDO 9. KAS...
Institutions Watched Bitcoin Fall 50%: Yet None of 15 Bitwise Surveyed Investors Cut Exposure
The NFT party is over and everybody now owes storage rent
Magic Eden Legacy Approvals Expose $5.7M in NFTs as Limit…
Anthropic Loses Pentagon Fight Ahead of Anticipated $2 Trillion IPO
Fed proposed stablecoin rule could trigger a 48-hour liquidation run
Bitcoin Supply Shock Debate Grows as IFP Turns Bullish
Bitcoin ETFs Add $134M as 7-Day Inflow Streak Hits $2.98B
US spot bitcoin ETFs took in $2.4 billion last week,ir best week since October
CleanSpark Secures $2.276 Billion Debt Financing for Georgia Data Center
Stock Tokenization Could Be Blockchain’s Amazon Moment
Coinbase Receives SEC Approval for Tokenized Stocks Trading in the US
StarkWare Challenge Reduces Quantum-Safe Bitcoin Compute Estimate by 79%
Bitcoin ETFs Notch Seven-Day Winning Streak as 2026 Flows Turn Green
SEC Issues Fresh Crypto Guidance on Staking Tokens, Buybacks, and the Howey Test
Tokenized Stocks Can Now Borrow Dollars: Aave V4 Opens Equities Hub on Base
Washington has $114 billion reasons to want Tether around
Circle and Tether Freeze $318,000 From Bitget Hack as Loss…
Jack Dorsey’s Block Brings Lightning Network to x402
Backpack SECURITIES-ISSUED $EWY, THE TOKENIZED ISHARES MSCI SOUTH KOREA ETF, GOES LIVE ON...
AMD Stock Surges 190%: Is It Better Than Nvidia?
How Crypto Stopped Waiting for Congress and Learned to Love the Regulators
Morpho CEO Clarifies Misleading Post on Curator Business Model
Morpho CEO Attributes Controversial Post to AI Marketing Tool
Ethereum Price Analysis: ETH Eyes $3K, but These Major Hurdles Stand in the Way
Balancer fork’s 6 million BAL ask could cut holders’ redemption value
Fed stablecoin proposal would make circulation a capital cost for supervised issuers
UNI Price Rally Could Have More Room After Q3 Breakout
SEC Staff Clarifies How Crypto Promises Affect Securities Treatment
A federal appeals court ruled Ohio and Tennessee can enforceir sports betting laws
Fidelity's Jurrien Timmer says Bitcoin has started a new bull market after holding $60K, and his...
Bitcoin spot ETFs see $5.3 billion in cumulative inflows after US Treasury increases long-term bond buybacks
Nearly $15B is moving off LayerZero, now a $292M lawsuit puts its security model on trial
Evercrest Technologies, the company behind KelpDAO, has sued LayerZero Labs, its Canadian affiliate, and CEO Bryan Pellegrino in British Columbia over April's $292 million rsETH exploit.
The claim alleges negligent misrepresentation, negligence and defamation, seeks aggravated and punitive damages, and says Kelp users have withdrawn more than $650 million since the attack.
Pellegrino has called the suit meritless. By Aug. 4, projects tied to roughly $14.5 billion in assets had announced moves from LayerZero to Chainlink's CCIP, nearly 50 times the amount stolen.
The lawsuit now asks a court to settle a responsibility dispute that customers have been pricing on their own since April.
Two failures had to line up
On April 18, attackers tricked LayerZero's verifier into approving a forged cross-chain transfer. LayerZero's incident report traces the intrusion to a developer who was socially engineered into cloning a malicious GitHub repository in March.
The attackers reached LayerZero's RPC environment, poisoned two internal nodes, and knocked an external RPC provider offline, so the verifier signed a message built on false source-chain data and 116,500 rsETH left Kelp's bridge.
That compromise succeeded because Kelp's bridge required approval from a single verifier, LayerZero's own, leaving one party able to authorize the release. The on-chain signature check worked as designed, since the signature was valid and simply attested to false information.
LayerZero's report splits the blame accordingly, assigning the number of required verifiers to the application and the compromised RPC layer to LayerZero as its operator.
| Security layer | What was supposed to happen | What failed | Who controlled that layer |
|---|---|---|---|
| Verifier count | Multiple independent verifiers could reject a bad message | Kelp required only LayerZero's verifier | Application / Kelp |
| RPC data | Verifier receives accurate source-chain state | Attackers poisoned LayerZero-operated RPC infrastructure | LayerZero |
| Independent check | A second verifier could disagree with false data | No second required verifier existed | Application configuration |
| Signature generation | Verifier signs only valid source-chain events | LayerZero's verifier signed false data | LayerZero-operated verifier |
| On-chain contract | Accept valid signatures from configured verifier set | Worked exactly as configured | Smart contract logic |
Kelp's claim targets what happened to LayerZero before the hack
Evercrest alleges LayerZero reviewed and approved the single-verifier setup in writing, including telling Kelp in February 2024 there was “no problem” with a default configuration.
The suit also alleges LayerZero warned another developer, USDT0, about risks in default verifier configurations while withholding a comparable warning from Kelp.
Those allegations have yet to be tested in court. LayerZero's account puts the choice on Kelp, saying the application had previously used a two-of-two configuration and moved to one-of-one.
LayerZero's verifier now refuses to sign on any channel where it's the only required signer, and the company requires multiple independent RPC sources across providers and geographies.
By Aug. 4, it had moved default pathways on both versions of its endpoint to a minimum of three verifiers, while applications can still build custom setups at the protocol level.
LayerZero also said in May that letting its own verifier act alone on high-value transfers had been a mistake, and it maintained the incident touched about 0.14% of the applications on its network.
LayerZero customers moved faster than the courts
BitGo accounted for the largest migration, with WBTC making up about $7.4 billion of the Aug. 4 tally, and it named CCIP its exclusive cross-chain provider for WBTC and the default for future BitGo-issued assets.
Mantle, Kelp's rsETH and Lombard added billions more, and Chainlink puts the total near $15 billion. Kelp says its own migration remains underway, so announced value and completed transfers are separate measures.
| Milestone | Associated asset value | Relative to $292M exploit | What it represents |
|---|---|---|---|
| Kelp exploit | $292M | 1.0× | Approximate value stolen |
| Early migration wave, May | >$3B | >10× | Projects announcing moves toward Chainlink |
| Migration wave, July | >$7B | >24× | Broader group of assets/projects changing infrastructure |
| Aug. 4 tally | ~$14.5B | ~49.7× | Associated asset value of announced LayerZero-to-Chainlink migrations |
| WBTC alone | ~$7.4B | ~25× | Largest single asset in Aug. 4 tally |
Wyoming's Stable Token Commission fully moved its FRNT state-issued token off LayerZero in August and signed a multi-year deal making CCIP its exclusive cross-chain provider.
Commission CISO Keith Lawhorn said Sept. 14 that the review began because of the Kelp attack and found problems with access controls, private key management, and incident disclosures, findings LayerZero has partly disputed.
The standard he described was infrastructure that is secure by default, with safeguards built into the product for a public issuer to rely on.
A responsibility gap that reaches past bridges
Kelp chose how many verifiers its bridge required, and LayerZero ran the infrastructure its only verifier depended on. Each party controlled a layer that failed, and the smart contract accepted the configuration both had allowed.
The same arrangement appears wherever an automated protocol depends on an identifiable company for oracles, custody, cloud hosting, or sequencing, since smart contracts turn whatever those services attest into irreversible outcomes.
A self-service provider can argue that a customer picked its own settings from the tools on offer. Kelp's allegation describes a provider that reviewed a client's architecture, called it acceptable, and operated the component that later broke, a harder position to defend if the allegations hold up.
LayerZero remains a large network, spanning 96 chains and $9.5 billion in bridged volume for the past 30 days, according to DefiLlama.
| Infrastructure model | Customer controls | Provider controls | Responsibility question if something fails |
|---|---|---|---|
| Pure self-service | Architecture, thresholds, configuration | Software/tooling only | Did the customer knowingly choose the risky setup? |
| Guided integration | Final deployment choice | Documentation, implementation advice, configuration review | Did provider guidance materially influence the risky choice? |
| Provider-operated component | Which component to use | Runtime infrastructure, RPCs, signers, oracles, custody | Did the operated service itself fail despite correct customer use? |
| Secure-by-default model | Limited customization | Enforced minimum redundancy and hardened defaults | Did the provider's minimum safeguards perform as promised? |
| Managed / institutional service | Business requirements | Configuration, monitoring, operational controls | Does provider assume more contractual or operational liability? |
If the court and the contracts behind the integration place responsibility for verifier choices on the application owner, configurable infrastructure keeps its place, with providers adding formal risk acknowledgments and hardened defaults like LayerZero's.
The migration wave would settle into a one-time repricing, and LayerZero's message volume and new asset launches would show whether its redesign restored confidence.
If Kelp substantiates its written-approval claims, approving custom security designs starts carrying legal exposure. Vendors could respond with warranties, indemnities and higher prices, or by refusing to sign off on nonstandard configurations.
More issuers adopting Wyoming's secure-by-default standard would steer institutional assets toward a smaller group of approved providers, trading configuration risk for concentration risk.
Kelp's bridge did exactly what its configuration told it to do, and LayerZero's verifier signed exactly what its compromised infrastructure told it was true. A court in British Columbia will now decide who owed the safeguards the industry spent five months adding.
Source: CryptoSlate