Evercrest sues LayerZero Labs over $292M rsETH bridge exploit
Update (Sep 26, 9:05pm): New draft specifies the bridge connected KelpDAO with Unichain, and clarifies LayerZero uses a Decentralized Verifier Network (DVN) structure, details not in published version.
A $292 million exploit on KelpDAO’s rsETH bridge in April has turned into a British Columbia lawsuit that asks a court to decide who bears responsibility when cross-chain infrastructure fails. Customers have already answered that question with their assets, moving roughly $14.5 billion away from LayerZero toward a rival network since the attack.
- Evercrest Technologies sued LayerZero Labs, its Canadian affiliate, and CEO Bryan Pellegrino in British Columbia.
- The April 18 exploit drained 116,500 rsETH worth $292 million from Kelp’s cross-chain bridge.
- Projects tied to roughly $14.5 billion in assets had announced moves to Chainlink’s CCIP by Aug. 4.
- $292M value of rsETH stolen in the April 18 Kelp bridge exploit
- $14.5B assets moved toward Chainlink’s CCIP by Aug. 4, nearly 50x the exploit
- $7.4B WBTC’s share of the Aug. 4 migration, the largest single asset
- $650M Kelp user withdrawals since the attack, according to the lawsuit
Evercrest Technologies, the company behind KelpDAO, has sued LayerZero Labs, its Canadian affiliate, and CEO Bryan Pellegrino in a British Columbia court, according to CryptoSlate. The claim alleges negligent misrepresentation, negligence and defamation over an April 18 exploit that drained 116,500 rsETH worth $292 million from Kelp’s bridge, and it seeks aggravated and punitive damages. Kelp users have withdrawn more than $650 million since the attack, the lawsuit states.
Pellegrino has called the suit meritless.
Evercrest says LayerZero approved Kelp’s single-verifier setup in writing
On April 18, attackers tricked LayerZero’s verifier into approving a forged cross-chain transfer, letting 116,500 rsETH leave Kelp’s bridge. LayerZero’s own incident report traces the breach to a developer who was socially engineered in March into cloning a malicious GitHub repository, giving attackers access to LayerZero’s RPC environment and letting them poison two internal nodes. That intrusion succeeded because Kelp’s bridge required sign-off from a single party, LayerZero’s own signing service, leaving no independent check on the false data it received.
Evercrest alleges LayerZero reviewed and approved that setup in writing, including telling Kelp in February 2024 there was “no problem” with the default arrangement. The suit further alleges LayerZero warned another developer, USDT0, about risks in default configurations while withholding a comparable warning from Kelp. Those allegations have yet to be tested in court.
LayerZero’s own account places the choice on Kelp, saying the application had previously run a two-of-two setup before moving to one-of-one. Its verifier now refuses to sign on any channel where it is the sole required signer, and the company requires multiple independent RPC sources across providers and geographies. By Aug. 4, default pathways on both versions of its endpoint required a minimum of three verifiers, though applications can still build custom configurations at the protocol level.
Nearly $14.5 billion has left LayerZero for Chainlink’s CCIP since the exploit
By Aug. 4, projects tied to roughly $14.5 billion in assets had announced moves from LayerZero to Chainlink’s CCIP, nearly 50 times the $292 million stolen in April. BitGo accounted for the largest single migration, moving WBTC representing about $7.4 billion of that total and naming CCIP its exclusive cross-chain
BlockWest is a news publication. Nothing here is investment advice. Read our disclaimer and editorial policy.
