KelpDAO has sued LayerZero and its co-founder Bryan Pellegrino after a bridge exploit that removed about $292 million worth of rsETH in April. The suit, filed by KelpDAO’s parent Evercrest Technologies in the Supreme Court of British Columbia, accuses LayerZero of negligent misrepresentation, negligence and defamation.
Lawsuit details
Evercrest says LayerZero reviewed and approved the bridge design in writing, telling the developer that the default setup was "good" and that there was "[n]o problem" using it. The filing states that LayerZero explicitly directed the use of a 1-of-1 verifier arrangement, meaning only LayerZero’s own decentralized verifier network had to confirm a lock before minting could proceed.
Allegations and timeline
According to the claim, an attacker placed malware on a LayerZero developer’s computer on March 6, then manipulated the protocol’s nodes so they supplied false data to the verifier. On April 18 the attacker disabled the third-party nodes that the verifier also consulted, leaving it to rely solely on the compromised internal node. The verifier then reported that 116,500 rsETH had been locked on Unichain when none had been, allowing the bridge to mint unbacked tokens. Evercrest says it halted the bridge within an hour and blocked a second attempt.
The lawsuit also points to later statements from LayerZero that described the single-verifier setup as a mistake and admitted it had allowed its DVN to act as a 1-of-1 verifier for high-value transactions. Evercrest claims it received no comparable warning about the risks, unlike another developer who was advised to run its own verifier.
LayerZero's response
Bryan Pellegrino has called the claim meritless and said he will defend the case in Vancouver. LayerZero has not provided a public comment on the filing, reiterating its earlier position that the loss stemmed from KelpDAO’s bridge configuration rather than a flaw in its own infrastructure.
Why it matters
The case highlights the growing legal exposure of cross-chain protocols when bridges suffer large-scale exploits. It also raises questions about how responsibility is allocated between protocol developers and the projects that integrate their technology, especially when security recommendations are disputed after a loss.




