KelpDAO Sues LayerZero Following $292 Million rsETH Exploit

Evercrest Technologies, the company behind the DeFi protocol KelpDAO, has filed a civil lawsuit against LayerZero Labs and its co-founder Bryan Pellegrino. The dispute stems from an April cross-chain bridge exploit involving approximately 116,500 rsETH, worth around $292 million at the time of the incident.

The lawsuit was filed in the Supreme Court of British Columbia. Evercrest alleges negligence, negligent misrepresentation, and defamation. The company argues that the attack resulted from a failure in LayerZero’s security infrastructure rather than a vulnerability within KelpDAO’s own systems.

LayerZero disputes that position. All allegations outlined in the lawsuit remain claims by the parties and have not been proven in court.

The Dispute Centers on the Bridge’s Security Configuration

The incident occurred on April 18 and involved rsETH moved through infrastructure connected to Unichain. One of the central issues in the case is the configuration of the Decentralized Verifier Network (DVN) used to validate messages between blockchains.

Under the configuration in question, only one DVN was required to approve a message, and that verifier was operated by LayerZero. This differs from a multi-DVN model, where several independent verifiers may be required to confirm a message before it can be processed.

Evercrest claims that LayerZero was aware of the selected configuration and approved it before the bridge launched. According to the lawsuit, LayerZero representatives told the company in February 2024 that using the default DVN configuration should not create a problem.

Evercrest also alleges that in March, LayerZero recommended using a similar setup that had already been implemented in another cross-chain bridge.

According to the plaintiff, these communications gave it reason to believe that the chosen architecture provided an adequate level of security.

Evercrest Says the Risks Were Not Properly Disclosed

The lawsuit states that LayerZero described its DVN infrastructure as a systеm supported by redundancy, monitoring, and alerting mechanisms.

Evercrest also claims that LayerZero had previously described the consequences of a compromised DVN mainly as the risk of incorrectly validating a message, but did not warn that using a single verifier could create a critical single point of failure for the entire bridge.

According to Evercrest’s account, the attack occurred at around 17:35 UTC on April 18. The company alleges that the attacker gained access to LayerZero’s infrastructure after using social engineering to cause malware to be installed on a LayerZero developer’s computer.

These circumstances have not been established by the court. It has also not been confirmed that LayerZero’s systems were compromised in the manner described.

The Parties Disagree Over the Single-DVN Model

Evercrest also claims that LayerZero provided different levels of security warnings to different developers.

In particular, the plaintiff alleges that another project, USDT0, had previously been warned about the risks associated with default or simplified DVN configurations, while KelpDAO allegedly did not receive a comparable warning before the exploit.

This part of the case could become important to the negligence and misrepresentation claims. Evercrest is effectively arguing that LayerZero may have understood the relevant risks but failed to communicate them consistently to all partners.

LayerZero takes a different position and says that relying on a single DVN runs contrary to its recommended security model, which favors multiple independent verifiers.

As a result, one of the key issues for the court may be what guidance was actually provided to KelpDAO and whether the project reasonably relied on that guidance.

The Lawsuit Goes Beyond the Technical Cause of the Exploit

Evercrest is also challenging public statements made by LayerZero and Bryan Pellegrino after the incident.

The company disputes the claim that KelpDAO’s configuration directly contradicted LayerZero’s recommended multi-DVN security model.

Evercrest also alleges that public comments by Pellegrino, which placed responsibility for the chosen setup on KelpDAO, damaged the protocol’s reputation.

On that basis, the company added defamation claims alongside its allegations of negligence and negligent misrepresentation.

The lawsuit also seeks additional and punitive damages, although it does not specify the amount of compensation that may ultimately be awarded.

Pellegrino has publicly rejected the allegations, calling them baseless and stating that he intends to defend his position.

KelpDAO Says the Exploit Had Major Business Consequences

According to Evercrest, the impact of the incident extended well beyond the assets directly affected by the exploit.

The company claims that users withdrew more than $650 million in assets from KelpDAO following the incident.

Evercrest also links the exploit to disruption of its stablecoin strategy, which ultimately contributed to the discontinuation of the sbUSD product.

Following the attack, the company also began migrating rsETH to a different cross-chain security model in order to reduce its dependence on the infrastructure involved in the exploit.

The Case Could Influence How Responsibility Is Shared in Cross-Chain Infrastructure

The dispute between Evercrest and LayerZero goes beyond a single exploit. It raises a broader question about how responsibility should be divided between a cross-chain infrastructure provider and an application that chooses a specific security configuration.

If the court is required to determine who should bear responsibility for the consequences of a compromised verifier, the case could also have implications for other projects that rely on external messaging protocols and bridge infrastructure.

Particular attention is likely to focus on who determined the security architecture, what guidance was provided before launch, and how clearly the risks of relying on a single verifier were communicated.

The lawsuit is still at an early stage, and the claims made by both sides remain disputed. However, the case already highlights how important questions of responsibility, security configuration, and transparency are becoming in the rapidly growing cross-chain infrastructure sector.

27.09.2026, 20:23
  1. Category: 
Comments for news "KelpDAO Sues LayerZero Following $292 Million rsETH Exploit"
No comments
Commenting is available only to registered users
Choose file
Give
Get
Exchange
days
hours