TL;DR
-
Evercrest Technologies filed a civil claim against LayerZero and co-founder Bryan Pellegrino in British Columbia.
-
The lawsuit concerns an April exploit involving 116,500 rsETH, then worth approximately $292 million.
-
Evercrest alleges LayerZero endorsed the bridge’s single-verifier security configuration.
-
The company also accuses LayerZero and Pellegrino of unfairly blaming KelpDAO after the attack.
Evercrest Technologies, the company behind decentralized finance protocol KelpDAO, has filed a lawsuit against LayerZero Labs and co-founder Bryan Pellegrino over an April bridge exploit involving approximately $292 million in rsETH.
The notice of civil claim was filed Thursday in the Supreme Court of British Columbia. It names LayerZero Labs Ltd., LayerZero Labs Canada Inc. and Pellegrino as defendants and alleges negligent misrepresentation, negligence and defamation.
Evercrest argues that the April 18 exploit resulted from a failure within LayerZero’s security infrastructure rather than a vulnerability in KelpDAO’s own systems. LayerZero disputes the allegations, and the claims have not been tested or proven in court.
Lawsuit Centers on $292 Million rsETH Exploit
The dispute stems from an attack involving 116,500 rsETH bridged through Unichain. The assets were worth approximately $292 million when the exploit occurred.
According to the filing, the affected bridge used a one-of-one decentralized verifier network configuration. A DVN is responsible for verifying messages sent between blockchains through LayerZero’s cross-chain messaging infrastructure.
Under the configuration in question, only one DVN—operated by LayerZero—was required to approve a message. That differs from a multi-DVN model, under which several independent verifiers may need to confirm a message before it can be processed.
Evercrest alleges that LayerZero reviewed and endorsed the one-of-one configuration before the bridge went live. The company says LayerZero told it in written communications dated February 2, 2024, that using the default DVN setup posed no problem.
The filing further claims that LayerZero directed Evercrest on March 21, 2024, to use the same one-of-one structure implemented by another bridge.
Evercrest argues that these communications led it to believe the configuration was appropriate and adequately protected by LayerZero’s infrastructure.
The lawsuit alleges that LayerZero described its DVN system as operating with redundancy across multiple locations and supported by monitoring and alert mechanisms.
Evercrest also claims LayerZero represented that even if a DVN became compromised, the primary risk would be that it might fail to verify a message correctly. According to the filing, LayerZero did not warn Evercrest that using the company’s DVN as the bridge’s only verifier could create a critical security vulnerability.
The attack occurred at approximately 17:35 UTC on April 18, the lawsuit states. Evercrest alleges that the attacker gained access to LayerZero’s security infrastructure after using social engineering to install malware on a LayerZero developer’s computer.
These assertions remain allegations contained in the civil claim. The court has not determined whether LayerZero’s systems were compromised in the manner described or whether the company bears responsibility for the loss.
LayerZero Allegedly Warned Another Developer
Evercrest also alleges that LayerZero treated other developers differently when discussing DVN security.
According to the claim, LayerZero had previously warned USDT0 about risks associated with default DVN configurations. Evercrest argues that it did not receive a similar warning before the rsETH exploit, despite relying on LayerZero’s own verifier infrastructure.
This alleged difference in guidance forms an important part of Evercrest’s negligent-misrepresentation case. The company is effectively arguing that LayerZero possessed relevant knowledge about the risks but failed to communicate it consistently.
LayerZero, however, has maintained that using only one DVN contradicted its recommended security model, which favors multiple independent verifiers. That disagreement over what guidance was provided—and whether KelpDAO reasonably relied on it—is likely to become a central issue in the litigation.
Lawsuit Challenges LayerZero’s Public Response
The case extends beyond the technical cause of the exploit. Evercrest is also challenging statements made by LayerZero and Pellegrino afterward.
Evercrest disputes LayerZero’s public assertion that KelpDAO’s configuration directly contradicted the company’s recommended multi-DVN model. It also alleges that Pellegrino publicly blamed the protocol for relying on a one-of-one setup, damaging KelpDAO’s reputation.
On that basis, Evercrest is seeking damages for defamation in addition to its negligence and negligent-misrepresentation claims. It has also requested aggravated and punitive damages, although the filing does not establish what amount the court might award.
Pellegrino rejected the allegations in a post on X, describing the claim as meritless and saying he would defend himself.
KelpDAO Reports Significant Business Impact
Evercrest says the exploit caused substantial damage beyond the assets directly affected by the attack.
According to the filing, KelpDAO users have withdrawn more than $650 million in assets since the incident. The company also says the breach disrupted its stablecoin strategy, leading to the eventual discontinuation of its sbUSD product.
Evercrest has since started moving rsETH to an alternative cross-chain security standard, reducing its reliance on the infrastructure involved in the exploit.
The case could have wider implications for cross-chain protocols and the developers that use them. At its core, the dispute raises questions about how responsibility should be divided between an infrastructure provider and an application that selects a particular security configuration.
Hassan Maishera