AI

KelpDAO Developer Sues LayerZero Over $292M Bridge Exploit

· Decrypt

KelpDAO Developer Sues LayerZero Over $292M Bridge Exploit

In brief

  • Evercrest Technologies has filed a civil claim against LayerZero, its Canadian arm and co-founder Bryan Pellegrino in the Supreme Court of British Columbia.
  • The claim alleges negligent misrepresentation, negligence and defamation over April's $292 million exploit.
  • It says the attack began with malware on a LayerZero developer's computer six weeks before any funds moved.

The company behind KelpDAO has sued LayerZero and its chief executive over the exploit that drained $292 million from the restaking protocol in April, alleging LayerZero endorsed in writing the exact bridge configuration it later blamed for the loss.

Evercrest Technologies filed the notice of civil claim in the Supreme Court of British Columbia on Wednesday, naming LayerZero Labs Ltd., LayerZero Labs Canada Inc. and co-founder Bryan Pellegrino, who is sued personally over posts on Telegram and X. It pleads negligent misrepresentation, negligence and defamation, and seeks aggravated and punitive damages.

KelpDAO's bridges ran a 1-of-1 setup, meaning LayerZero's own verifier network was the only party confirming that tokens had been locked on one chain before equivalent tokens were minted on another.

Evercrest says that was LayerZero's instruction. LayerZero told it in February 2024 that its draft code was "good" and that there was "[n]o problem" using the default configuration, according to the filing, and in March 2024 explicitly directed it to use a 1-of-1 setup with LayerZero's own verifier. In January 2025, LayerZero said that even if a verifier were compromised, the most it could do was fail to verify a message correctly.

The filing also says LayerZero warned a separate developer, USDT0, about risks in its default verifier configurations in late 2024 or early 2025, prompting that developer to run its own. Evercrest says it received no comparable warning.

The exploit began inside LayerZero, on the claim's account. An attacker put malware on a LayerZero developer's computer on March 6, then tampered with LayerZero's nodes so they fed false readings to its verifier. On April 18 the attacker disabled the third-party nodes the verifier also used, so it was told 116,500 rsETH had been locked on Unichain when nothing had. With one verifier required, the tokens were minted unbacked. Evercrest says it paused the bridges within about an hour and blocked a second attempt.

The defamation claims turn on what followed. LayerZero's incident statement said the single-verifier setup contradicted a multi-DVN model it had "consistently recommended to all integration partners," and Pellegrino wrote that "[n]obody should be relying on sole DVN." Days later, the filing says, LayerZero admitted it had "made a mistake by allowing [its] DVN to act as a 1-of-1 DVN for high-value transactions."

Evercrest claims damages including a 2,000 ETH contribution to restore rsETH's backing, more than $650 million withdrawn since the exploit, and a fall in the KERNEL token that drew regulator and exchange warnings.

Pellegrino tweeted that the claim "continues to be meritless" and that he would meet Evercrest in Vancouver to defend himself. None of the allegations has been tested in court, and no response to the claim has been filed.