


Original Author: Yihao Tian, Esq.
On April 18, 2026, an attacker stole 116,500 rsETH from KelpDAO's cross-chain bridge in 46 minutes, worth approximately $292 million. This was the largest DeFi security incident of 2026. The stolen tokens were promptly deposited as collateral into lending protocols like Aave V3, borrowing roughly $236 million in ETH, resulting in bad debts of $177 million to $200 million on Aave, triggering a chain reaction affecting over nine DeFi protocols, and causing Aave's Total Value Locked (TVL) to evaporate by about $6 billion overnight.
The events of the incident have been widely reported and will not be repeated here. In fact, the author himself has tens of thousands of USDT locked up... so the author was quite motivated when conducting research. This article explores a different question: From a civil legal perspective, who should bear responsibility? Can victims actually receive compensation?
The answer is far more complex than the initial finger-pointing within the crypto community. After a systematic analysis of the applicable legal frameworks, I conclude that KelpDAO and LayerZero Labs bear concurrent liability, with the fault ratio roughly 60% for KelpDAO and 40% for LayerZero. Additionally, the liability cap clauses in both protocols' Terms of Service are almost certainly unenforceable.
Discussions surrounding this attack always start with the same debate: Was it KelpDAO's fault (choosing a 1-of-1 DVN configuration) or LayerZero's fault (its DVN's RPC infrastructure being poisoned)?
The answer is: both are at fault.
(I) What KelpDAO Did Wrong
LayerZero's cross-chain messaging protocol uses a Decentralized Verifier Network (DVN) to verify whether messages sent from one blockchain to another are authentic. The protocol is designed to be highly flexible: each application deployed on LayerZero can choose how many DVNs need to reach consensus to trust a message. LayerZero's own documentation recommends at least a 2-of-3 configuration, meaning at least two out of three independent verifiers must confirm a message before it is accepted.
KelpDAO chose the absolute minimum configuration: 1-of-1. One verifier. Zero fault tolerance.
This meant anyone who could compromise, deceive, or manipulate that single verifier could forge arbitrary cross-chain messages, including one instructing KelpDAO's bridge to release its entire rsETH reserve to an address controlled by the attacker. And that's precisely what happened.
This is quite absurd: KelpDAO's bridge secured approximately $1.6 billion in total value across over twenty blockchain networks. The protocol chose to protect these assets with a single point of failure, equivalent to using a padlock on a bank vault while the manufacturer explicitly recommends at least a three-lock system.
Under traditional tort law, this analysis is quite straightforward. The Restatement (Second) of Torts defines negligence as conduct that falls below the standard of care established by law for the protection of others against unreasonable risk of harm. [1] For professional actors, and protocol operators managing billions of dollars in user assets certainly fall into this category, the standard of care is elevated to the skill and knowledge ordinarily possessed by members of the profession. [2]
The classic risk-utility analysis framework was formulated by Judge Learned Hand of the U.S. Court of Appeals for the Second Circuit in United States v. Carroll Towing Co. [3]: if the burden of adequate precautions (B) is less than the probability of harm (P) multiplied by the gravity of the resulting injury (L), then failing to take those precautions constitutes negligence. That is: when B < P × L, failure to take precautions is negligent.
In this case, the equation is beyond dispute:
No rational protocol operator could justify using a 1-of-1 configuration for assets of this magnitude. The cost of prevention was trivial, while the expected harm was catastrophic.
It is worth noting that industry peer practices provide an important benchmark. SparkLend set a Loan-to-Value (LTV) ratio of 72% for rsETH, and Fluid set it at approximately 75%, both significantly lower than Aave's 93%. This conservatism may reflect the industry's awareness of the underlying bridge risk associated with rsETH. If lending protocols were cautious about the risk of the rsETH bridge, then the operator of the bridge itself, KelpDAO, should be held to an even higher security standard. The reality was the opposite: the party operating the bridge chose the lowest possible security configuration.
An important defense also needs discussion: the on-chain transparency defense. The 1-of-1 DVN configuration is publicly verifiable on-chain data. Any technically capable user could check the bridge's security parameters by querying the LayerZero EndpointV2 contract. KelpDAO might argue that since the configuration was public, users had the opportunity (and responsibility) to assess the bridge's security before depositing assets. This constitutes a factual assumption of risk defense, distinct from contractual ToS waivers (analyzed in Part II). The strength of this defense depends on how a court views the "reasonableness" standard for DeFi users. Can an average DeFi user reasonably be expected to review a bridge's DVN configuration before depositing assets? For institutional users and technically sophisticated "whales," this defense may be viable; for ordinary retail investors, it is significantly weaker.
(II) What LayerZero Did Wrong
But KelpDAO's configuration choice alone was insufficient to cause the loss. The attack also required the attacker to trick LayerZero's DVN into signing a verification for a transaction that never occurred. It is at this point that LayerZero's legal risk becomes clear.
According to a detailed analysis published by Cos, founder of the well-known blockchain security firm SlowMist, [4] this attack was not a breach of the DVN's private keys or an exploitation of the LayerZero protocol logic. The attacker targeted the DVN's upstream data source: the RPC nodes used by the DVN to read blockchain state.
The attack was executed in five steps:
1. The attacker obtained the list of RPC nodes used by the LayerZero DVN.
2. The attacker compromised two independent RPC node clusters, replacing the legitimate op-geth binary with a trojanized version.
3. The trojanized binary employed selective spoofing: it returned fabricated data only to requests originating from the DVN's IP address. All other IP addresses, including LayerZero's own Scan monitoring service, received genuine data. This IP-based selective response pattern made the poisoning completely invisible to routine monitoring.
4. The attacker launched DDoS attacks against the uncompromised RPC nodes, forcing the DVN to failover to the poisoned nodes.
5. After completing the fraudulent verification, the malicious binary self-destructed and wiped all logs, eliminating forensic evidence.
This point is crucial: LayerZero operated this DVN. This was not a passive software library deployed by KelpDAO. LayerZero was actively running the verification infrastructure, choosing RPC providers, configuring failover logic, and signing verification proofs. When the DVN read fabricated on-chain state from a poisoned RPC node and signed a verification for a non-existent transaction, it was LayerZero's infrastructure that failed.
Moreover, this attack vector is not novel. As Cos pointed out: "RPC poisoning attacks are an old trick; exchanges experienced this years ago." [5]
Under the Restatement (Second) of Torts, an actor must recognize the risks that a reasonable person in their position would recognize. [6] RPC poisoning is a well-documented category of attack within the blockchain security community. A reasonable infrastructure provider operating a DVN to secure billions of dollars in cross-chain assets should have implemented countermeasures, including: (a) diversifying RPC sources across multiple independent providers and geographically distributed locations; (b) implementing cross-verification between RPC nodes to detect data inconsistencies; (c) monitoring for IP-based selective response patterns; (d) hardening failover logic to avoid falling back to untrusted nodes under DDoS pressure; and (e) implementing anomaly detection for DVN verification requests (e.g., flagging unusually large transfer amounts).
Furthermore, the non-delegable duty doctrine applies here. According to the Restatement (Second) of Torts, certain safety-critical functions cannot be fully delegated to third parties, and the party undertaking the duty has a responsibility to ensure its adequate performance. [7] When LayerZero holds itself out as providing verification infrastructure for high-value cross-chain transactions, it cannot escape liability by pointing to RPC providers as independent contractors. LayerZero chose these providers, configured the failover logic, and operated the verification nodes. Liability rests with the operator.
A comparable traditional legal concept is the liability of financial infrastructure operators. SWIFT provides messaging infrastructure for interbank communications globally. If SWIFT's message verification system were compromised, leading to the execution of fraudulent transfer instructions, SWIFT could not absolve itself merely because "the protocol itself had no vulnerabilities." It operates the verification infrastructure, and that operational activity carries a duty of care commensurate with the value being protected. LayerZero's role in the DeFi ecosystem is highly analogous: it is not merely a software licensor; it is an operator of cross-chain message verification infrastructure.
The constructive notice effect of the Drift Protocol attack also warrants consideration. On April 1, 2026, Drift Protocol suffered a $285 million cross-chain attack, occurring just 17 days before the KelpDAO attack. While the specific attack vector of the Drift attack may differ from this case (this requires further verification), it sent a clear signal to the entire cross-chain infrastructure industry: cross-chain bridge infrastructure was under active attack by advanced persistent threats (APTs). In this context, LayerZero, as one of the largest cross-chain messaging protocols, should have been on high alert. The failure to enhance RPC infrastructure security following the Drift attack further supports a finding of negligence.
LayerZero's strongest defense is the sophistication of a state-sponsored attacker. The combination of elements in this attack—binary file replacement, IP-based selective spoofing, DDoS-forced failover, and post-incident self-destruction—represents an exceptional level of operational complexity, potentially approaching the level of the SolarWinds supply chain attack. According to Section 302B of the Restatement (Second) of Torts, the risk of highly abnormal criminal intervention lies beyond the scope of reasonable prevention. If a court determines that the complexity of this attack exceeded the reasonable standard of care for a private sector infrastructure provider, LayerZero's negligence liability could be substantially reduced or eliminated.
However, the counter-argument against this defense is equally strong: as Cos pointed out, each individual component of this attack was well-known, even if their combination was novel. RPC poisoning is a known technique. DDoS is a known technique. Binary file replacement is a known technique. A reasonable infrastructure operator should have defended against these known individual threats, even if it could not foresee their precise combination.
(III) Concurrent Causation and the 60/40 Fault Allocation
This is a classic case of concurrent causation. KelpDAO's 1-of-1 configuration and LayerZero's RPC infrastructure failure were both necessary conditions for the success of the attack. Removing either one would have caused the attack to fail:
Under the Restatement (Second) of Torts, when two or more causes combine to produce a single indivisible harm, each is considered a "substantial factor" in causing the harm, and each tortfeasor is held liable. [8] The attacker's criminal conduct does not break the causal chain because targeting a single point of failure in a bridge is precisely the foreseeable risk that multi-DVN recommendations are designed to prevent. [9]
New York and California, the most likely jurisdictions for any such lawsuit, employ pure comparative fault systems. [10] This means each defendant's liability is reduced by their percentage of fault, but they are not completely absolved.
So, how should fault be allocated? I assess it at approximately KelpDAO 60% / LayerZero 40%, based on three reasons:
First, KelpDAO made an active choice to select 1-of-1 despite LayerZero's explicit recommendation for at least 2-of-3. This was a governance decision, not a technical limitation imposed by LayerZero. The protocol had the ability to choose higher security but did not. This active choice carries significant weight in any comparative fault analysis.
Second, the 1-of-1 configuration was the fundamental prerequisite for the attack. Without it, the attacker would have faced a fundamentally different (and far more difficult) challenge. The RPC poisoning attack succeeded only because there was a single verification path to compromise. A multi-DVN configuration with independent infrastructure would have created a defense in depth that this attack could not defeat.
Third, however, LayerZero's liability cannot be zero. LayerZero operated the DVN whose infrastructure was compromised. RPC poisoning is a known attack vector. The Drift Protocol attack 17 days prior had put the entire cross-chain industry on high alert. And LayerZero's own defense that "the protocol was not breached," while technically accurate at the protocol level, obscures the fact that LayerZero's operational infrastructure was the direct instrument of the loss.
The 40% allocation to LayerZero reflects the reality that it operated the infrastructure that failed, using an architecture known to be susceptible to compromise, without implementing standard countermeasures against a well-documented category of attack.
Both KelpDAO and LayerZero maintain Terms of Service (ToS) with extremely aggressive liability limitations. KelpDAO caps its total liability at the greater of the amount paid in the preceding twelve months or $200. [11] LayerZero's cap is $50. [12] Both include standard "AS IS" disclaimers and broad risk assumption clauses.
If these cap provisions were valid, the entire civil liability analysis above would be an academic exercise. A $200 cap against a $292 million loss would render KelpDAO effectively immune from any meaningful recovery.
These cap provisions will not be upheld by a court. Here is why.
(I) The Doctrine of Unconscionability
Contract law has long recognized that certain terms are so fundamentally unfair that courts will refuse to enforce them. The doctrine of unconscionability, codified in the Restatement (Second) of Contracts, allows courts to void contract terms that are both procedurally and substantively unconscionable. [13]
Procedural unconscionability examines whether there was a meaningful opportunity to negotiate or reject the terms. DeFi Terms of Service are classic adhesion contracts: presented on a take-it-or-leave-it basis, with no opportunity for negotiation, often buried deep within a website that most users never visit. Most DeFi users interact with smart contracts directly through wallet interfaces like MetaMask, having never browsed the protocol's website, let alone read or agreed to multi-page ToS files.
The legal distinction between "clickwrap" and "browsewrap" agreements is well-established. [14] In Specht v. Netscape, [15] then-Judge Sotomayor (now Justice of the U.S. Supreme Court) held that a hyperlink to Terms of Service below a download button, not prominently displayed, was insufficient to constitute user consent. In Nguyen v. Barnes & Noble, [16] the Ninth Circuit similarly held that a website must provide conspicuous notice and an opportunity to review the terms; merely using the website is insufficient.
DeFi protocol interactions are closer to the situation in Specht than to Meyer v. Uber [17] (where a prominent registration page with a clear link to the terms was held to be effective notice). Whether on-chain smart contract interactions constitute consent to off-chain website ToS has not yet been directly ruled upon by any court, but the weight of existing browsewrap jurisprudence strongly disfavors enforcing terms absent an affirmative act by the user.
Substantive unconscionability examines whether the terms are so one-sided as to "shock the conscience." A $200 liability cap against a $292 million loss, a ratio of approximately 1:1,460,000, is textbook substantive unconscionability. LayerZero's $50 cap presents an even more extreme ratio. In the landmark case Williams v. Walker-Thomas Furniture, [18] the court held that when a party has no meaningful choice, courts will not enforce terms that are "unreasonably favorable to the drafter." The Restatement's commentary confirms that "gross disparity in the exchange" is direct evidence of unconscionability. [19]
(II) The Gross Negligence Exception
Even if a court finds the ToS generally enforceable, liability limitation clauses do not protect against gross negligence or willful misconduct. This is an established principle under both New York and Delaware law.
The Restatement (Second) of Contracts states that a term exempting a party from tort liability for reckless or intentional conduct is unenforceable as against public policy. [20] The New York Court of Appeals has repeatedly confirmed that exculpatory clauses do not cover gross negligence, applying a "reckless disregard" standard. [21]
Does KelpDAO's 1-of-1 DVN configuration constitute gross negligence? The argument is strong. Gross negligence requires a reckless disregard for a known substantial risk, going beyond mere failure to exercise ordinary care. KelpDAO chose the lowest possible security configuration for a bridge protecting over $1 billion in assets, against the explicit recommendation of the infrastructure provider. The risk that a single point of failure could be compromised was well-documented. The gap between 1-of-1 (zero fault tolerance) and 2-of-3 (33% fault tolerance) is not a marginal risk difference; it is a fundamental one.
If a court characterizes the choice of 1-of-1 as reckless rather than merely negligent, the $200 cap becomes void regardless of the outcome of the unconscionability analysis.
The gross negligence exception is important because it bypasses the threshold debate over ToS validity. Even if a court finds that users did consent to the ToS (e.g., through a clickwrap mechanism), and even if the court finds that a $200 cap is not unconscionable in a general commercial context (e.g., for institutional-level users), the gross negligence exception still applies independently. It is a public policy doctrine, not subject to the consent of the parties. Under New York law, this principle has been repeatedly affirmed, [21] forming the most robust second line of attack against the ToS.
(III) Securities Law Preemption
There is a third path to invalidating the ToS caps, and it is the most powerful.
If rsETH is classified as a security under federal law, then liability cap provisions and arbitration clauses are void by operation of law. The Securities Act provides that "any condition, stipulation, or provision binding any person to waive compliance with any provision of this title" is void. [22] The Exchange Act contains the same anti-waiver provision. [23] These provisions cannot be contracted around. They preempt the Federal Arbitration Act. They are not subject to state law unconscionability analysis. They are mandatory commands of federal law.
Does rsETH meet the definition of a security? Under the foundational test established in Howey, [24] an investment contract exists when there is (1) an investment of money, (2) in a common enterprise, (3) with an expectation of profits, (4) derived from the efforts of others.
rsETH meets each element. Users deposit ETH (investment of money) into a pooled restaking strategy on EigenLayer (common enterprise). rsETH generates yield through restaking rewards (expectation of profits). And the restaking strategy, operator selection, and bridge infrastructure are entirely managed by the KelpDAO team, with no control held by individual holders (efforts of others).
The complication lies in the split holding in the Ripple case. [25] In 2023, the Southern District of New York distinguished between direct institutional sales (which were securities) and programmatic secondary market sales on public exchanges (which were not). Most rsETH transactions occur on secondary markets—DEX swaps, Aave deposits—rather than through direct purchases from KelpDAO. Under the Ripple framework, secondary market purchasers might not satisfy the "efforts of others" prong. However, Ripple is only a district court decision, currently on appeal to the Second Circuit, and its applicability to liquid staking tokens has not been tested.
If securities classification succeeds, it completely transforms the recovery landscape. The ToS caps disappear. The arbitration clause disappears. Direct purchasers acquire private rescission rights. [26] All purchasers who relied on KelpDAO's statements about bridge security could bring fraud claims. [27]
A special explanation of the power of this legal tool is necessary here: Under U.S. law, arbitration clauses and class action waivers are typically strongly protected. The U.S. Supreme Court in AT&T v. Concepcion [28] and Epic Systems v. Lewis [29] established that the Federal Arbitration Act preempts state law invalidation of class action waivers in arbitration agreements. In American Express v. Italian Colors Restaurant, [30] the Supreme Court further narrowed the "effective vindication doctrine," ruling that an arbitration clause can be overturned only if it prevents the assertion of statutory rights, and that high litigation costs alone are insufficient grounds for overturning it.
This means that if LayerZero's arbitration clause stands, it would force victims into individual arbitration, with each person's claim capped at $50, functionally equivalent to a complete liability barrier. No rational plaintiff would initiate individual arbitration proceedings for $50 in compensation.
However, the securities law anti-waiver provisions provide a pathway around this obstacle. If rsETH is a security, federal law directly nullifies the arbitration clause and class action waiver, without needing to invoke the unconscionability doctrine, and without having to fight the preemptive effect of the FAA. This is why securities classification is the most critical "nuclear weapon" in the entire analysis.
The RPC node providers whose infrastructure was poisoned occupy a unique position in this chain of liability. They provided the false data that the DVN relied upon. But their liability is constrained by several factors.
Under the Restatement (Second) of Torts, a supplier of information in the course of business who fails to exercise reasonable care is liable for economic loss caused by justifiable reliance, but only to a foreseeable "limited group" of persons that the supplier intends to reach or knows the recipient intends to reach. [31] In New York, Credit Alliance v. Arthur Andersen [32] further limited the liability of information suppliers to third parties with a three-prong test.
Applied to this case, the RPC providers' liability likely runs only to LayerZero (who directly selected and relied upon them), not extending downstream to KelpDAO users or rsETH holders. This means the RPC providers' liability is primarily a contribution claim by LayerZero—a mechanism for LayerZero to pass its 40% fault share downstream—rather than a direct recovery path for victims.
There is also a practical obstacle: the identities of the RPC providers have not been publicly disclosed. They themselves may be victims of a state-sponsored cyber attack. The sophistication of the attack (binary file replacement, IP-based selective spoofing, DDoS, self-destructing binary) suggests operational capabilities beyond those of ordinary cybercriminals. If the providers are themselves victims of a state-level attack, establishing their negligence would be difficult, as the standard of care does not require ordinary commercial entities to defend against military-grade intrusions.
The most likely outcome: RPC provider liability remains behind the scenes, potentially relevant in contribution proceedings between KelpDAO and LayerZero, but not a primary path for victim recovery.
The attack stole $292 million from KelpDAO's bridge. But the contagion effects—$177 million to $200 million in bad debts, a $6 billion TVL decline, principal losses for depositors—were amplified by Aave's governance decisions.
(I) Aggressive Parameter Settings
In January 2026, Aave governance passed Proposal 434, increasing the e-mode Loan-to-Value (LTV) ratio for rsETH from 92.5% to 93%. This meant for every $100 of rsETH collateral, users could borrow $93 of ETH.
Compare Aave's competitors: SparkLend set the LTV for rsETH at 72%. Fluid set it at approximately 75%. The gap is not minor; the 21-percentage-point difference reflects fundamentally different risk philosophies.
At a 93% LTV, the safety margin was only 7%. Any decline in collateral value exceeding 7% would generate bad debts, borne by Aave's depositors (not the borrowers). For a collateral asset whose value depended on a cross-chain bridge with a single point of failure, a 7% safety margin was objectively inadequate.
(II) Legal Framework: The DAO as a General Partnership
The legal landscape for DAO governance liability has changed dramatically in the past two years.
In Samuels v. Lido DAO, [33] a federal court in California ruled in 2024 that Lido DAO could reasonably be characterized as a general partnership under California law. Governance token holders who participated in voting might be treated as general partners, personally liable for partnership obligations. In Sarcuni v. bZx DAO, [34] another California federal court reached a similar conclusion, ruling that participating DAO token holders were jointly and severally liable.
Under California's Revised Uniform Partnership Act (RUPA), partners owe each other fiduciary duties of care and loyalty, [35] and are jointly and severally liable for all partnership obligations. [36]
(III) The Caremark Oversight Duty
Delaware's fiduciary duty framework, applied by analogy to DAO governance, provides the most relevant standard of care. In the landmark Caremark case, [37] the court established that fiduciaries have an affirmative duty to establish and monitor compliance and risk management systems. Stone v. Ritter [38] affirmed that a Caremark oversight claim requires a showing that the fiduciaries either (1) completely failed to establish a monitoring system, or (2) having established such a system, consciously failed to attend to its output, with conscious disregard constituting bad faith.
Aave's situation falls into the second category. Aave was not lacking a risk management system; it had engaged Chaos Labs for three years. However, on April 6, 2026, Chaos Labs publicly departed, with its founder citing "fundamental disagreements over risk strategy." [39] Twelve days later, the attack occurred.
This coincidence is powerfully suggestive in evidence: Aave's risk manager left due to strategic disagreements, and within two weeks, the precise category of risk that aggressive LTV parameters amplified—collateral value collapse—materialized on a catastrophic scale. Under Van Gorkom, [40] the business judgment rule is rebutted when directors approve a major decision "without adequate information." If Aave governance approved the 93% LTV without any assessment of rsETH's bridge security, specifically without knowing that the rsETH bridge relied on a zero-fault-tolerance 1-of-1 DVN, this is precisely the kind of uninformed decision-making that Van Gorkom targets.
(IV) Practical Limitations
The fiduciary duty theory against Aave governance is legally strong but practically limited. Anonymous governance voters are unreachable; you cannot collect damages from anonymous wallet addresses. The Lido DAO case itself is still actively being litigated (dispositive motions are scheduled for November 2026) and could be overturned.
But not all governance participants are anonymous. Major institutional delegates—venture funds, protocol treasuries, professional governance services—if they voted in favor of Proposal 434, are identifiable and potentially personally liable under the Lido/bZx partnership framework. For these identifiable delegates, the theory is actionable.
An explanation of why the Caremark duty is so critical is needed here. In traditional corporate law, the Caremark duty represents a minimal oversight responsibility. Directors do not need to micromanage company operations, but they must ensure a reasonable system of information reporting and compliance monitoring exists. When directors either (1) completely fail to establish such a system, or (2) have established a system but consciously ignore its warning signals, they breach the Caremark duty.
In Aave's context, this duty has a very specific meaning: When Aave governance accepted rsETH as collateral, did it review the security architecture of the underlying rsETH bridge? Specifically, did any governance participant, risk committee member, or delegate know that the rsETH bridge relied on a 1-of-1 DVN configuration, i.e., zero fault tolerance? If the answer is no (which is highly probable given the loose practices of current DeFi governance), then Aave governance set parameters for tens of billions of dollars' worth of collateral with a mere 7% safety margin, without adequate knowledge of the risk. This is precisely the "uninformed decision-making" that Van Gorkom targets.
Going further: Chaos Labs' departure is not merely a coincidence. Chaos Labs had served as Aave's risk manager for three years, thoroughly familiar with Aave's risk framework. When its founder publicly cited "fundamental disagreements over risk strategy," this constituted a significant warning signal. A prudent governance system would have initiated a review of risk parameters immediately after its risk management service provider left due to strategic disagreements, or at least paused onboarding new high-risk collateral, especially in the immediate aftermath of the Drift Protocol attack. Aave governance took no such action.
The broader implication of the Aave governance issue is systemic. If DeFi governance voters can be held personally liable for risk parameter decisions that amplify losses from an attack, this would fundamentally change how governance participants approach collateral onboarding and LTV settings. The 93% LTV for a single-point-of-failure bridge asset could become the classic case study of governance negligence—the DeFi equivalent of the Caremark red flag.
A key timeline to watch: dispositive motions in Samuels v. Lido DAO are scheduled for November 2026. If the California federal court confirms that Lido DAO constitutes a general partnership and that governance token holders face personal liability, this would clear the legal path for similar lawsuits against Aave governance participants. Conversely, if the Lido precedent is overturned, the entire theoretical framework for DAO governance liability discussed in this article would face a major setback.
Legal liability is one question. Actual recovery is another. The strongest defendant in law (KelpDAO, 60% fault) may be the hardest to recover from (offshore DAO, unknown entity structure). The most accessible defendant in practice (LayerZero Labs Canada Inc., 40% fault) is a real company with identifiable directors and over $120 million in venture capital funding.
This creates a recovery tier in which practical considerations trump pure liability allocation:
Tier 1: LayerZero Labs Canada Inc. A real Canadian federal corporation (corporation number 13558479, Vancouver), [41] with two directors and ample funding. It is the most viable corporate litigation target. Key advantages: identifiable entity, governed by Canadian corporate law, assets subject to seizure. Key obstacles: comparative fault reduction (40% × $292 million = ~$117 million maximum exposure), potential arbitration clause, Canadian business judgment rule protections.
Tier 2: Audit and Security Firms. KelpDAO and LayerZero almost certainly engaged security audit firms to review the bridge contracts. Under the Restatement (Second) of T