Evercrest Technologies, the company behind KelpDAO, has sued LayerZero Labs and co-founder Bryan Pellegrino over the April exploit that resulted in the loss of 116,500 rsETH worth approximately $292 million. The civil claim turns a months-long dispute over bridge security and verifier configuration into litigation over who bears responsibility for one of 2026’s largest DeFi exploits. The case was filed in the Supreme Court of British Columbia on September 24.
The notice of civil claim names LayerZero Labs Ltd., LayerZero Labs Canada Inc. and Pellegrino. Evercrest alleges negligent misrepresentation, negligence and defamation, while also seeking aggravated and punitive damages. The approximately $292 million figure describes the value of rsETH affected by the April 18 attack rather than a separately verified fixed damages demand.
Lawsuit Challenges LayerZero’s Security Account
At the center of the case is KelpDAO’s use of a 1-of-1 Decentralized Verifier Network configuration, meaning LayerZero Labs’ DVN was the sole verifier required to approve the relevant cross-chain messages. Evercrest alleges that LayerZero reviewed and endorsed that configuration in writing before the exploit and failed to disclose risks that later proved material. According to the filing, LayerZero told the team in 2024 that the configuration presented “no problem” and later directed it toward the same single-verifier structure used elsewhere.
LayerZero disputes that interpretation. Its official incident report says an attacker socially engineered a LayerZero developer on March 6, stole session credentials and gained access to the company’s RPC cloud environment. The attacker then manipulated internal RPC nodes and disrupted an external provider, causing LayerZero’s DVN to receive false blockchain-state information. The compromised DVN subsequently produced a valid attestation for a forged cross-chain message.
LayerZero nevertheless maintains that the catastrophic loss depended on KelpDAO’s verification topology. With no second independent DVN required, the destination contract accepted the sole attestation and released 116,500 rsETH. The technical record therefore contains two distinct failure layers: compromised LayerZero-operated infrastructure and an application configuration that required only that compromised verifier. LayerZero has since changed its operating policy and says its DVN will no longer participate as the sole required attestor on a channel.
That security debate has already influenced other interoperability decisions. Solv Protocol later moved roughly $700 million of tokenized Bitcoin from LayerZero to Chainlink CCIP following a cross-chain security review. The Kelp incident became an industry reference point for assessing single-verifier dependencies and fault tolerance in bridge design.
Litigation Extends an Already Complex Recovery Process
The exploit also created problems well beyond the bridge itself. The stolen rsETH entered DeFi lending markets, triggering recovery efforts involving Aave, Arbitrum and other participants. CryptoCurrencyMagazine previously covered Aave’s attempt to unfreeze roughly $71 million in ETH linked to the Kelp exploit. The British Columbia case adds a separate liability dispute on top of those asset-recovery proceedings.
Evercrest also alleges that LayerZero and Pellegrino damaged KelpDAO after the incident by publicly assigning responsibility to its single-DVN configuration. The filing says more than $650 million was withdrawn from KelpDAO following the exploit and cites additional business consequences. Those claims remain allegations and have not been tested by the court. Pellegrino has called the case “meritless” and said he intends to defend himself and LayerZero in Vancouver.
The dispute comes as bridge exploits continue to expose different types of verification failure. The Verus-Ethereum bridge attack, for example, involved proofs that were cryptographically valid but insufficiently tied to economically backed payouts. The common lesson is that message validity, verifier redundancy and source-to-destination reconciliation represent separate security controls rather than interchangeable protections.
The next concrete milestone is LayerZero’s formal response to the British Columbia claim and the court’s eventual treatment of Evercrest’s allegations. The case could provide an unusually detailed legal test of how responsibility is divided when an infrastructure provider’s systems are compromised but an application-level security configuration determines the scale of the resulting loss. For now, the technical compromise is documented, but the legal allocation of fault between KelpDAO and LayerZero remains unresolved.
