KelpDAO Sues LayerZero and Co-Founder Over $292 Million Bridge Exploit

Evercrest says LayerZero gave it specific assurances before the exploit: in February 2024 it described the draft code as “good” and said there was “[n]o problem” with the default verifier configuration; in January 2025, it allegedly said a compromised verifier could do no more than fail to verify a message correctly.
The filing alleges LayerZero warned another developer, USDT0, about risks in its default verifier configuration in late 2024 or early 2025, but gave Evercrest no comparable warning.
The lawsuit seeks aggravated and punitive damages, and names Pellegrino personally in connection with posts he made on Telegram and X.
The exploit’s broader market impact included Aave’s total value locked falling by $8.45 billion within two days; LayerZero also linked the attack to the TraderTraitor subgroup of North Korea’s Lazarus Group.
Evercrest Technologies, the company behind KelpDAO, sued LayerZero Labs and co-founder Bryan Pellegrino in British Columbia over a $292 million exploit in April 2024. Cryptopolitan reported that attackers created roughly 116,500 unbacked rsETH tokens by compromising LayerZero infrastructure. Evercrest claims LayerZero endorsed a risky single-verifier setup without warning of the dangers.
The lawsuit alleges negligence, negligent misrepresentation, and defamation. CryptoBriefing noted that LayerZero has blamed the single-verifier configuration, while Pellegrino called the claims meritless. No court has yet determined who bears responsibility for the breach.
Evercrest alleges LayerZero provided written assurances about the bridge's safety in the months before the attack. In February 2024, LayerZero described the draft code as "good" and said there was "[n]o problem" with the default verifier setup. In January 2025, Crypto Economy reported LayerZero allegedly told Evercrest that a compromised verifier could only fail to verify messages — not mint unbacked tokens.
The filing claims LayerZero treated other developers differently. MENAFN reported that LayerZero warned another protocol, USDT0, about risks in the default verifier configuration in late 2024 or early 2025. Evercrest says it received no comparable warning despite running a similar setup.
The April 18 exploit succeeded by compromising LayerZero infrastructure and manipulating verifier data. Attackers created 116,500 unbacked rsETH tokens worth roughly $292 million at the time. Decrypt reported that Evercrest paused the bridges and blocked a further attempted mint once the attack was discovered.
Evercrest is now moving rsETH transfers to a different cross-chain security system. The single-verifier configuration — where one entity validates all bridge transactions — left no backup if that verifier was compromised. LayerZero's endorsement of this risky setup is central to Evercrest's negligence claim.
The exploit triggered significant market turmoil. CryptoBriefing reported that Aave's total value locked fell by $8.45 billion within two days of the attack. LayerZero also linked the breach to TraderTraitor, a subgroup of North Korea's Lazarus Group.
Evercrest is seeking aggravated and punitive damages in the suit. Cryptopolitan reported that the filing names Pellegrino personally in connection with posts he made on Telegram and X. The allegations frame the case not just as a technical failure but also as a reputational attack on KelpDAO.
Publishers
24
Articles
14
Reach
38