Editor's Pick

Evercrest (KelpDAO) Files Civil Claim Against LayerZero and…

Evercrest, the entity associated with KelpDAO, has filed a civil claim in British Columbia against LayerZero and its co-founder and CEO Bryan Pellegrino, escalating a months-long dispute over the $292 million KelpDAO bridge attack.

The claim was filed in Canada on September 24. KelpDAO says it is seeking accountability for the April 18 attack on its rsETH cross-chain bridge, in which an attacker caused 116,500 rsETH to be released without a corresponding transaction on the source blockchain.

Pellegrino has rejected the claim, describing it as “meritless” and saying he intends to defend himself and LayerZero in Vancouver.

The allegations in Evercrest’s filing have not been adjudicated, and the lawsuit creates a legal forum for resolving a question the two sides have disputed since April: who bears responsibility when LayerZero-operated infrastructure is compromised but an application’s chosen verification configuration allows that compromise to become catastrophic?

$292 Million Attack Began Inside LayerZero Infrastructure

The underlying technical facts are unusually significant because LayerZero itself has acknowledged that attackers penetrated infrastructure operated by LayerZero Labs.

According to LayerZero’s final incident report, the breach began on March 6, when an attacker socially engineered a LayerZero developer and obtained session credentials. The attacker subsequently entered LayerZero’s RPC cloud environment and compromised internal RPC nodes.

On April 18, the attacker also disrupted an external RPC provider, forcing LayerZero’s Decentralized Verifier Network, or DVN, to rely on compromised internal infrastructure.

Those nodes falsely indicated that a legitimate cross-chain transaction had occurred. LayerZero’s DVN consequently generated a valid attestation for a forged message, causing KelpDAO‘s Ethereum bridge contract to release 116,500 rsETH — approximately $292 million at the time.

A subsequent attempt to extract another 40,000 rsETH, then worth roughly $95 million, was stopped after KelpDAO paused the affected contracts.

Mandiant, CrowdStrike and independent researchers attributed the attack to TraderTraitor/UNC4899, a North Korean threat actor.

Lawsuit Centers on Who Bears Responsibility

Where KelpDAO and LayerZero differ is responsibility for allowing the infrastructure compromise to produce the loss.

KelpDAO alleges LayerZero failed to adequately disclose technical weaknesses and risks, failed to prevent its security infrastructure from being compromised and had previously reviewed and approved KelpDAO’s deployment and configuration in writing. Those remain claims by the plaintiff rather than findings by the Canadian court.

LayerZero has argued that KelpDAO’s own configuration created the decisive single point of failure.

KelpDAO’s rsETH bridge used a 1-of-1 DVN configuration, meaning the LayerZero Labs DVN was the sole verifier required to approve cross-chain messages. Once that verifier received manipulated information, there was no independent verifier required to reject the forged transaction.

LayerZero says it had recommended using multiple independent DVNs and that a diversified configuration would have prevented the attack even after its own infrastructure was compromised.

Independent security analysis broadly confirms the technical mechanics. Blockaid concluded that the attack succeeded because the compromised LayerZero DVN was sufficient to authorize the message under KelpDAO’s 1-of-1 configuration. Chainalysis similarly found that the attacker compromised LayerZero-operated offchain infrastructure rather than exploiting KelpDAO or LayerZero smart-contract code.

The lawsuit now shifts that technical dispute into the courts.

Its significance could extend beyond recovering losses from one exploit. Cross-chain protocols increasingly allow applications to customize their own security configurations while infrastructure providers operate critical components underneath them.

The Evercrest case could therefore test how responsibility is allocated when both layers matter: an infrastructure provider suffers a security compromise, while an application’s configuration determines how much damage that compromise can cause.

For now, Evercrest’s allegations remain unproven and LayerZero has made clear that it will contest them.