Evercrest Technologies, described by Decrypt as the company behind the KelpDAO liquid staking protocol, has filed a notice of civil claim in the Supreme Court of British Columbia against LayerZero Labs Ltd., LayerZero Labs Canada Inc. and co-founder Bryan Pellegrino, who is sued personally. The claim concerns an April exploit of the rsETH bridge that drained 116,500 rsETH, worth roughly $292 million at the time, and pleads negligent misrepresentation, negligence and defamation while seeking aggravated and punitive damages, according to Decrypt. KelpDAO said LayerZero failed to disclose risks in its technology and to prevent attackers from compromising its infrastructure, and that LayerZero had reviewed and endorsed its deployment and configuration in writing before the exploit, according to Cointelegraph. Pellegrino said the claim "continues to be meritless" and that he would meet the plaintiffs in Vancouver to defend himself, according to Decrypt and CoinDesk. No allegation has been tested in court, and Decrypt reports that no response to the claim had been filed.
Evercrest, the company behind KelpDAO, sues LayerZero and co-founder Pellegrino in British Columbia over $292 million bridge exploit
Evercrest Technologies, described by Decrypt as the company behind the KelpDAO liquid staking protocol, has filed a notice of civil claim in the Supreme Court of British Columbia against LayerZero Labs Ltd., LayerZero Labs Canada Inc. and co-founder Bryan Pellegrino, who is sued personally. The claim concerns an April exploit of the rsETH bridge that drained 116,500 rsETH, worth roughly $292 million at the time, and pleads negligent misrepresentation, negligence and defamation while seeking aggravated and punitive damages, according to Decrypt. KelpDAO said LayerZero failed to disclose risks in its technology and to prevent attackers from compromising its infrastructure, and that LayerZero had reviewed and endorsed its deployment and configuration in writing before the exploit, according to Cointelegraph. Pellegrino said the claim "continues to be meritless" and that he would meet the plaintiffs in Vancouver to defend himself, according to Decrypt and CoinDesk. No allegation has been tested in court, and Decrypt reports that no response to the claim had been filed.
The dispute follows an attack on KelpDAO's LayerZero-powered rsETH bridge. Decrypt reports the attacker placed malware on a LayerZero developer's computer on March 6, tampered with LayerZero's nodes so they fed false readings to its verifier, and on April 18 disabled third-party nodes the verifier also used, causing it to be told 116,500 rsETH had been locked on Unichain when nothing had been. Cointelegraph also dates the attack to April 18. CoinDesk dates the attack to April 22 and reports that a North Korean hacking group allegedly carried it out, and that KelpDAO held nearly a fifth of the restaked token's circulating supply at the time.
At issue is the bridge's verification setup. Decrypt reports KelpDAO's bridges ran a 1-of-1 configuration in which LayerZero's own verifier network was the only party confirming that tokens had been locked on one chain before equivalent tokens were minted on another, and that Evercrest says this was LayerZero's instruction. According to the filing as reported by Decrypt, LayerZero told Evercrest in February 2024 that its draft code was "good" and that there was "[n]o problem" using the default configuration, and in March 2024 explicitly directed it to use a 1-of-1 setup with LayerZero's own verifier. In January 2025, LayerZero said that even if a verifier were compromised, the most it could do was fail to verify a message correctly, the filing states. Evercrest also says LayerZero warned a separate developer, USDT0, about risks in its default verifier configurations in late 2024 or early 2025, prompting that developer to run its own verifier, and that Evercrest received no comparable warning.
LayerZero has disputed that account. In its final incident report, LayerZero said attackers compromised its internal nodes and caused its verifier to approve a forged cross-chain message, and argued the loss was possible because Kelp's bridge relied on a single LayerZero decentralized verifier network as its only verification path, according to Cointelegraph. LayerZero said it had recommended using multiple DVNs and subsequently stopped acting as the sole required verifier for applications. Decrypt reports LayerZero's incident statement said the single-verifier setup contradicted a multi-DVN model it had "consistently recommended to all integration partners," that Pellegrino wrote "[n]obody should be relying on sole DVN," and that days later LayerZero admitted it had "made a mistake by allowing [its] DVN to act as a 1-of-1 DVN for high-value transactions."
The claim also covers statements made after the exploit. Decrypt reports the defamation claims turn on that period and that Pellegrino is sued personally over posts on Telegram and X.
Damage claims described by Decrypt include a 2,000 ETH contribution to restore rsETH's backing, more than $650 million withdrawn since the exploit, and a fall in the KERNEL token that drew regulator and exchange warnings. CoinDesk reports that the aftershocks spread across stablecoin markets, including forcing Aave to borrow $300 million to meet rising user demand for withdrawals, and that days later the exploit erased $20 billion in total value locked, exposing structural risks in DeFi according to experts, including those at JPMorgan. Cointelegraph reports losses of about $292 million at the time of the attack and, separately, that recovery hopes faded as the attacker laundered nearly all of the stolen funds.
KelpDAO said it has taken action since the incident to protect user assets, including migrating the rsETH bridge to a different cross-chain security standard. Cointelegraph reports the plan is to migrate to Chainlink's Cross-Chain Interoperability Protocol. Cointelegraph also reports it contacted LayerZero for further comment and received no response before publication.
Where sources differ
- The sources give different days for the filing or its announcement: Decrypt says the notice of civil claim was filed on Wednesday; CoinDesk attributes the announcement to a post on X on Thursday; Cointelegraph says KelpDAO made its statement on Friday.
- The date of the attack differs: Decrypt and Cointelegraph both date it to April 18, while CoinDesk dates it to April 22.
- The identity of the plaintiff is framed differently: Decrypt names Evercrest Technologies as the filer and describes it as the company behind KelpDAO, while Cointelegraph describes KelpDAO as having filed the lawsuit and CoinDesk reports Pellegrino referring to "Evercrest (KelpDAO)."
- Responsibility for the loss is contested: LayerZero attributes it to KelpDAO's use of a single verifier, while KelpDAO says LayerZero endorsed its configuration in writing and failed to warn it of risks.
- None of the sources establishes the amount of damages sought or the full list of remedies requested beyond aggravated and punitive damages.
- Whether the North Korean hacking group attribution reported by CoinDesk has been confirmed by any authority is not established, and CoinDesk describes it as alleged.
- No source establishes the outcome of fund recovery efforts beyond Cointelegraph's report that recovery hopes faded after nearly all of the stolen funds were laundered.
- Decrypt reports no response to the claim had been filed and that no allegation has been tested in court, but the sources do not establish whether or how LayerZero will formally respond.
- LayerZero did not respond to Cointelegraph's request for comment, and no source contains a detailed response from LayerZero's corporate entities as distinct from Pellegrino's personal statements.
- Decrypt — original — by Decrypt Agent
- Cointelegraph — by Cointelegraph by Ezra Reguerra
- CoinDesk — by Olivier Acuna