2026-09-25 CoinTelegraph

Bitget Breach Hits $388M as KelpDAO Sues LayerZero Over $292M Exploit

Crypto exchange Bitget has revised the impact of Thursday's security breach upward to $388 million, roughly $35 million higher than its initial $352 million estimate. The increase reflects a more complete accounting of assets affected across Ethereum Virtual Machine networks, the XRP Ledger, Zcash, and TRON, rather than additional unauthorized transfers, according to the exchange. Compromised assets included XRP, Ether (ETH), Tether's USDt (USDT), Zcash (ZEC), USDC, USDT0, XAUt, BNB, AVAX, and TRX. Bitget CEO Gracy Chen said preliminary evidence points to possible North Korean involvement. Withdrawals remain paused as the exchange investigates and runs a bounty program aimed at freezing or recovering stolen funds. The breach ranks among the largest in the industry, though it remains well below the approximately $1.5 billion stolen from Bybit in February 2025.

Separately, restaking protocol KelpDAO has filed a lawsuit against cross-chain infrastructure provider LayerZero and its co-founder and CEO Bryan Pellegrino over the roughly $292 million exploit of KelpDAO's rsETH bridge earlier this year. KelpDAO alleges that LayerZero failed to disclose security risks in its technology and failed to prevent attackers from compromising its infrastructure. The complaint also claims LayerZero had reviewed and endorsed KelpDAO's deployment and configuration in writing before the exploit occurred. "Our number one priority has always been and will remain the security of our users' assets," KelpDAO wrote, adding that it needs to "hold LayerZero and Mr. Pellegrino accountable for the harm they have caused."

Pellegrino rejected the claims as "meritless" and said he would defend the case in Vancouver. The lawsuit escalates a months-long dispute over responsibility for the loss, with LayerZero and KelpDAO each pointing to the other's configuration and infrastructure decisions as the root cause. The case is being closely watched across the DeFi sector, as its outcome could shape how liability is assigned for cross-chain bridge exploits going forward.

Together, the two incidents highlight a continued pattern of large-scale crypto security failures in 2026, with attackers exploiting both centralized exchange infrastructure and cross-chain bridging protocols. North Korean-linked threat actors remain a persistent suspect in major exchange breaches, while DeFi protocols are increasingly turning to litigation to recover losses or assign blame for bridge exploits that have cost the industry billions collectively.

Read Full Article at CoinTelegraph →

Related Tool

Find Your ID

Try Now →
Check My ID