Evercrest Technologies, the company behind liquid-restaking protocol KelpDAO, has sued LayerZero Labs and its co-founder Bryan Pellegrino in British Columbia, alleging that security failures in LayerZero’s cross-chain verification infrastructure enabled an April exploit involving 116,500 rsETH worth about $292 million at the time.
The civil claim, filed Thursday in the Supreme Court of British Columbia, seeks damages for negligent misrepresentation, negligence and defamation from LayerZero Labs Ltd., LayerZero Labs Canada Inc. and Pellegrino. Evercrest also seeks aggravated and punitive damages. The allegations have not been tested in court, and Pellegrino has said the case is meritless.
At the centre of the dispute is a 1-of-1 decentralized verifier network, or DVN, configuration used by the Unichain bridge. Evercrest says LayerZero reviewed and endorsed that arrangement before it was exploited, even though a single verifier created a concentrated point of failure for messages moving between chains.
A DVN is part of LayerZero’s cross-chain messaging framework. It verifies whether a message sent from one blockchain should be accepted and executed on another. A multi-DVN model requires confirmation from more than one verifier, creating redundancy that can reduce the chance that one compromised system approves a fraudulent transfer.
Claim disputes LayerZero’s account of bridge configuration
Evercrest’s filing says LayerZero represented the 1-of-1 configuration as the default DVN setup for the Unichain bridge and indicated it was safe to use. The lawsuit cites written communications dated Feb. 2, 2024, in which Evercrest says LayerZero stated there was “no problem” with the default arrangement.
The company also alleges that LayerZero directed it on March 21, 2024, to use the same 1-of-1 configuration deployed by another bridge. According to the claim, LayerZero presented its own DVN infrastructure as geographically redundant, backed by monitoring systems and alerts.
Evercrest says it was told that a compromise of a DVN could at worst lead to a message failing verification. The company alleges it was not warned that a configuration relying on LayerZero’s own single DVN could permit a more serious failure, including the acceptance of fraudulent cross-chain messages.
The lawsuit argues that LayerZero should have recommended the use of multiple independent DVNs. It further alleges that LayerZero had warned another developer, USDT0, about risks associated with default DVN configurations before the April exploit.
That allegation could become a critical part of the case. If Evercrest can establish that LayerZero identified comparable risks for another project but did not provide the same warning to KelpDAO, the dispute would move beyond a technical disagreement over bridge design and toward questions about what security information LayerZero shared with users of its infrastructure.
Alleged social-engineering attack led to exploit
Evercrest says the attack occurred at approximately 17:35 UTC on April 18. The claim alleges that an attacker obtained access to LayerZero’s security infrastructure after using social engineering to install malware on a developer’s computer.
The lawsuit attributes the exploit to that alleged infrastructure breach rather than to a vulnerability in KelpDAO’s own smart contracts or internal systems. That distinction shapes the entire legal case: Evercrest is arguing that its protocol relied on security assurances from LayerZero and suffered losses when those assurances proved inadequate.
Cross-chain bridges have repeatedly faced scrutiny because they often combine smart contracts with off-chain operational infrastructure, including validators, verifiers, key-management systems and cloud services. A blockchain transaction may appear valid on-chain if the underlying verification network approves it, even where the approval itself resulted from a compromised server or credential.
Evercrest’s claim says the attacker exploited the bridge’s reliance on the single DVN configuration. It does not establish liability, but it places the practical limits of bridge redundancy under legal scrutiny. A bridge designed around one verifier may be simpler to run, but compromise of that verifier can leave few barriers between an attacker and the destination chain.
Fallout reaches KelpDAO products and rsETH migration
The filing says the incident disrupted KelpDAO’s stablecoin plans and contributed to the subsequent sunset of its sbUSD product. Evercrest also says rsETH, KelpDAO’s liquid-restaking token, has begun migrating to an alternative cross-chain security standard.
That migration suggests the project is seeking to reduce dependence on the verification structure at issue in the claim. For users, the operational impact of a bridge breach can extend well beyond the initial exploit, affecting token transfers, collateral arrangements, liquidity routes and the ability of related products to maintain normal operations.
Evercrest also alleges that users withdrew more than $650 million in KelpDAO assets after the exploit. The claim presents those withdrawals as part of the financial and reputational damage suffered by the protocol.
The case includes a defamation component tied to public statements made after the incident. Evercrest disputes LayerZero’s assertion that the 1-of-1 configuration “directly contradicts” its recommended multi-DVN model. It also challenges comments attributed to Pellegrino that blamed KelpDAO for selecting a single-verifier setup.
Pellegrino responded to the allegations in a post on X, saying they were meritless and that he would defend himself. LayerZero’s formal response to the civil claim was not included in the material provided.
A legal test for shared responsibility in bridge security
The dispute may turn on technical records as much as public statements: the configuration guidance provided to Evercrest, the security representations surrounding LayerZero’s DVN services, internal warnings about single-verifier designs, and the circumstances of the alleged malware compromise.
The case also puts attention on how infrastructure providers communicate risk to protocols building on their systems. Cross-chain applications frequently depend on services that are partly controlled by external providers, leaving responsibility divided among smart-contract developers, verification operators and the teams that configure security thresholds.
Evercrest’s claim seeks to place a substantial share of that responsibility with LayerZero. Whether the court accepts that position will depend on evidence yet to be presented, but the filing already frames the April exploit as a dispute over security design, warnings and operational control rather than simply another bridge failure.
To understand how major exploits reshape crypto safety standards, explore essential crypto safety standards every trader should know today.
Disclaimer: The content on this page is provided for general informational purposes only and does not represent the views or financial advice of Toobit. We make no guarantees regarding the accuracy or completeness of this information and shall not be held liable for any errors, omissions, or outcomes resulting from its use. Investing in digital assets involves risk; users should independently evaluate their financial situation and the risks involved. For further details, please consult our Terms of Service and Risk Disclosure.
