KelpDAO Sues LayerZero Over $292 Million rsETH Exploit

Evercrest alleges LayerZero endorsed the bridge configuration later blamed for the attack
TL;DR
- Evercrest Technologies, the company behind KelpDAO, sued LayerZero entities and co-founder Bryan Pellegrino over the rsETH exploit.
- The claim alleges negligent misrepresentation, negligence and defamation tied to LayerZero’s security infrastructure and bridge guidance.
- LayerZero disputes KelpDAO’s account, while Pellegrino said the lawsuit “continues to be meritless.”
Trade smarter on Jupiter, Solana’s leading DEX built for fast execution and deep liquidity.
Swap tokens at competitive rates, route across multiple liquidity sources automatically, and access perpetuals, DCA, and advanced trading tools — all in one place!
Evercrest Technologies, the company behind KelpDAO, has filed a civil claim in British Columbia against LayerZero Labs Ltd., LayerZero Labs Canada Inc. and LayerZero co-founder Bryan Pellegrino over the April 18, 2026 exploit that involved 116,500 rsETH worth about $292 million at the time. Evercrest alleges the attack resulted from LayerZero’s security infrastructure and says LayerZero had reviewed and endorsed the bridge configuration used before the exploit. Pellegrino disputes the allegations.
The lawsuit, filed in the Vancouver registry before British Columbia’s top trial court, alleges negligent misrepresentation, negligence and defamation. Evercrest is seeking ordinary damages as well as aggravated and punitive damages.
Evercrest Says LayerZero Approved 1-of-1 DVN Setup
KelpDAO’s bridge used a 1-of-1 decentralized verifier network, or DVN, configuration. Under that structure, LayerZero’s verifier was the only verifier required to approve a cross-chain message before rsETH locked on one chain could be minted on another.
Evercrest alleges LayerZero did more than supply the underlying infrastructure. The company says LayerZero reviewed and endorsed the configuration later used by KelpDAO’s Unichain bridge and failed to warn KelpDAO that relying on LayerZero’s verifier alone created a security risk.
The filing says LayerZero told Evercrest on February 2, 2024, that there was “no problem” with using the default DVN configuration. Evercrest further alleges that LayerZero instructed it on March 21, 2024, to use the same 1-of-1 configuration as another bridge.
Evercrest also cites security representations LayerZero made about its verifier infrastructure. A January 2025 security pitch described the system as redundant, monitored and distributed across multiple locations, with monitoring and alerting designed to detect problems. LayerZero also allegedly represented that even if a verifier were compromised, the most it could do was “fail to verify a message correctly.”
The lawsuit contrasts KelpDAO’s treatment with guidance allegedly given to the USDT0 developer in late 2024 or early 2025. Evercrest says LayerZero warned that developer about risks associated with default verifier configurations. The developer subsequently operated its own verifier, according to the claim.
Evercrest alleges the attacker first compromised a single LayerZero developer’s computer after using social engineering to install malware. The company’s filing states: “The exploit was not a failure of KelpDAO’s systems. It was a failure of LayerZero’s own security infrastructure.”
The attack also affected KelpDAO’s product plans. The protocol’s planned sbUSD stablecoin was shut down or sunset following the incident. KelpDAO also began moving rsETH to another cross-chain standard and selected Chainlink CCIP in May 2026 for that migration.
Despite the news, LayerZero’s ZRO token was up more than 6% intraday.

LayerZero Disputes Responsibility for the Configuration
The dispute extends to who was responsible for choosing the bridge’s security model. LayerZero’s post-mortem said KelpDAO’s setup “directly contradicts” the multi-DVN model LayerZero advocates, while Evercrest says LayerZero had previously reviewed and recommended the disputed configuration.
Pellegrino challenged KelpDAO’s version of events in May 2026, calling it “completely untrue.” He said KelpDAO had originally launched using LayerZero’s multi-DVN default and later changed the configuration itself to 1-of-1.
Following the filing of the lawsuit, Pellegrino again rejected Evercrest’s claims on X, saying: “The claim continues to be meritless,” and indicating that he would defend himself.
LayerZero has since banned the 1-of-1 configuration. The parties’ competing accounts now center on whether KelpDAO independently weakened its bridge security, as Pellegrino argues, or relied on a setup that LayerZero itself reviewed, recommended and represented as safe, as Evercrest alleges. No court finding on negligence, defamation or responsibility for the exploit is established by the filing itself.
This article has been refined and enhanced by ChatGPT.