LayerZero Faces $292M KelpDAO Bridge Exploit Lawsuit From Evercrest

1 hour ago 3 sources negative

Key takeaways:

  • Lawsuit tests whether 1-of-1 DVN setups shift liability to infrastructure providers like LayerZero.
  • rsETH holders should watch DVN diversification as a key risk metric for cross-chain bridge safety.
  • Bearish sentiment for ZRO may persist until courts clarify shared liability in bridge exploits.

Evercrest, the entity behind KelpDAO, has filed a civil claim in British Columbia against LayerZero Labs and CEO Bryan Pellegrino, escalating a months-long dispute over the April 18, 2026 attack on KelpDAO's rsETH cross-chain bridge. The claim was filed in Canada on September 24 and seeks accountability for the release of 116,500 rsETH, valued at approximately $292 million at the time, without a corresponding transaction on the source blockchain. Pellegrino has called the lawsuit 'meritless' and said he will defend the case in Vancouver.

The underlying breach began on March 6, when an attacker socially engineered a LayerZero developer and obtained session credentials. The attacker then compromised internal RPC nodes in LayerZero's cloud environment. On April 18, after disrupting an external RPC provider, the attacker forced LayerZero's Decentralized Verifier Network to rely on compromised internal infrastructure. Those nodes falsely indicated a legitimate cross-chain transaction had occurred, causing the DVN to generate a valid attestation for a forged message. KelpDAO's Ethereum bridge contract then released the rsETH. A subsequent attempt to extract another 40,000 rsETH, worth roughly $95 million, was stopped after KelpDAO paused affected contracts. Mandiant, CrowdStrike and independent researchers attributed the attack to the North Korean threat actor TraderTraitor/UNC4899.

The lawsuit centers on a critical legal question: who bears responsibility when a protocol's infrastructure is compromised but an application's chosen verification configuration allows that compromise to become catastrophic? KelpDAO alleges LayerZero failed to adequately disclose technical risks, prevent the security compromise, and had previously reviewed and approved its deployment configuration in writing. LayerZero argues the loss was caused by KelpDAO's 1-of-1 Decentralized Verifier Network configuration, which made LayerZero Labs' DVN the sole verifier required to approve cross-chain messages. The company says it recommended multiple independent DVNs and that a diversified configuration would have prevented the attack. Independent analysts from Blockaid and Chainalysis broadly confirmed that the compromised LayerZero DVN was sufficient to authorize the forged message under KelpDAO's setup.

The case could set an important precedent for cross-chain protocols, where applications customize security configurations while infrastructure providers operate critical components. For now, Evercrest's allegations remain unproven, and LayerZero has indicated it will contest the claim.

Disclaimer

The content on this website is provided for information purposes only and does not constitute investment advice, an offer, or professional consultation. Crypto assets are high-risk and volatile — you may lose all funds. Some materials may include summaries and links to third-party sources; we are not responsible for their content or accuracy. Any decisions you make are at your own risk. Coinalertnews recommends independently verifying information and consulting with a professional before making any financial decisions based on this content.