The crypto industry is entering a period in which technical failures are increasingly becoming legal battles, while the rapid expansion of prediction markets is forcing regulators to confront a basic question: when does an event contract become gambling?
KelpDAO’s developer has filed a civil claim against LayerZero and its co-founder Bryan Pellegrino over a $292 million exploit, while New York has sued Polymarket over alleged violations of state gambling laws, following a similar case against Kalshi.
The KelpDAO dispute centers on an April 18 attack involving 116,500 rsETH, worth approximately $292 million at the time.
Register for the next Tekedia Mini-MBA.
Register for Tekedia AI in Business Masterclass.
Join Tekedia Capital Syndicate and co-invest in great global startups.
LayerZero’s own incident report says the attack involved a compromise of internal LayerZero Labs RPC infrastructure alongside a denial-of-service attack against a third-party RPC used by the LayerZero Labs Decentralized Verifier Network.
The report notes that the affected application had been changed from a two-of-two verification arrangement to a one-of-one configuration, leaving a single verifier responsible for message confirmation.
Evercrest Technologies, the company behind KelpDAO, now argues that LayerZero had endorsed the configuration that later became central to the incident. According to the civil claim reported by Decrypt, Evercrest alleges negligent misrepresentation, negligence and defamation, including claims involving statements attributed to Pellegrino.
LayerZero and Pellegrino dispute the allegations, and the claims have not been established by a court. The significance extends beyond the individual dispute. Cross-chain bridges depend on complex combinations of smart contracts, validators, verification systems and infrastructure.
When hundreds of millions of dollars disappear, determining responsibility becomes difficult because security failures can involve both application-level configuration and infrastructure operated by external providers.
The KelpDAO case therefore places a broader question before the industry: how should liability be allocated when developers rely on third-party interoperability infrastructure?
At the same time, prediction markets are confronting a different kind of legal uncertainty. New York Attorney General Letitia James and Governor Kathy Hochul announced a lawsuit against Polymarket, alleging that its prediction-market platform operates as an unlicensed gambling business in the state.
New York argues that the contracts involve uncertain outcomes and therefore fall within the state’s gambling laws. The state is seeking to stop the alleged operation, recover gains and obtain fines and restitution.
The case follows New York’s July lawsuit against Kalshi, which makes similar allegations. The state says Kalshi allows users to wager on events including sports, elections and cultural outcomes without obtaining a New York gaming license.
Kalshi has challenged the state’s position, arguing that prediction markets fall under federal rather than state oversight. That federal-state conflict could become particularly important as prediction markets expand.
The platforms describe event contracts as financial-market products, while New York is treating them under its gambling framework. Polymarket has also been lobbying regulators in Europe and the United Kingdom to recognize its contracts as financial products rather than gambling instruments.
The KelpDAO and prediction-market cases reveal a maturing crypto sector confronting an unavoidable reality: technological innovation can move faster than legal frameworks. Bridges need clearer responsibility standards.
While prediction markets need clearer boundaries between financial contracts and gambling. In both cases, courts and regulators may ultimately determine where those boundaries lie.
Yuga Labs VP 0xQuit Recovers 23,155 NFTs Worth $5.7M in Limit Break Exploit As ENA, NEAR and LINK Rally
The crypto market is once again illustrating the two forces that continue to define the digital-asset industry: rapid innovation and persistent security risk. While tokens such as ENA, NEAR and LINK have helped drive a broader market rally.
The sector is simultaneously confronting another major exploit involving non-fungible tokens, highlighting how quickly confidence can shift when infrastructure is compromised.
At the centre of the latest security incident is Limit Break’s Payment Processor V2, which was exploited in an attack that affected thousands of NFTs. Yuga Labs vice president and prominent NFT security researcher 0xQuit responded by whitehatting 23,155 NFTs valued at more than $5.7 million.
The intervention was aimed at protecting assets that could otherwise have been drained or transferred by attackers exploiting the vulnerability. The scale of the intervention is significant because NFTs are not merely static digital images.
Depending on the collection and infrastructure supporting them, they can represent ownership rights, access, memberships, gaming assets or other forms of digital property. A vulnerability in a payment processor can therefore create consequences far beyond a conventional software malfunction.
Whitehat interventions have become an important part of the crypto ecosystem. Security researchers can sometimes act before malicious actors have fully exploited a vulnerability, moving or securing assets to prevent theft.
In this case, 0xQuit’s intervention demonstrates the increasingly important role that independent researchers and security specialists play in protecting decentralized markets. The recovery was not complete.
Around 660 WETH remained unrecovered, leaving a gap between the value protected and the assets that could not be secured. That distinction matters because the existence of a successful whitehat response does not eliminate the underlying vulnerability or guarantee that every affected asset can be recovered.
The incident arrives as the wider cryptocurrency market is experiencing renewed momentum. ENA, NEAR and LINK have emerged among the tokens contributing to the rally, demonstrating that investor attention remains strong despite the sector’s continuing security challenges.
Market rallies can quickly change sentiment, encouraging traders to increase exposure as momentum builds. ENA’s performance is particularly relevant because Ethena has developed a major presence within the stablecoin and decentralized-finance ecosystem.
NEAR remains closely associated with blockchain infrastructure and decentralized applications, while Chainlink’s LINK occupies an important position in the oracle sector, connecting blockchain-based applications with external data and real-world information.
The contrast between rising token prices and a major NFT exploit captures the complexity of the current crypto market. Capital can move aggressively toward promising assets even while weaknesses remain embedded in the infrastructure connecting users, applications and digital ownership.
The rally may create opportunities, but the exploit provides an equally important reminder that price momentum is only one part of the market equation. Smart-contract risk, protocol architecture, custody mechanisms and third-party infrastructure can all influence the real risk behind an apparently attractive digital asset.
For the broader industry, the Limit Break incident reinforces the importance of security audits, responsible disclosure and rapid-response systems. As billions of dollars move through increasingly complex blockchain applications, vulnerabilities can become financially significant almost immediately.
The crypto market’s latest rally therefore comes with a contradiction: enthusiasm is returning to digital assets, but security remains an unresolved structural challenge. The whitehat recovery of more than $5.7 million demonstrates what coordinated intervention can accomplish.
The unrecovered WETH shows that prevention remains more valuable than recovery once an exploit begins.



