In mid-April, attackers compromised a cross-chain bridge that relied on LayerZero’s verification service. By deceiving a developer into cloning a malicious repository, the perpetrators poisoned LayerZero’s RPC nodes, causing the verifier to sign a message based on falsified source-chain data. The forged approval released 116,500 rsETH, valued at roughly $292 million, from the KelpDAO bridge. The bridge’s smart-contract logic required only a single LayerZero verifier, allowing the compromised signature to pass.

Legal claims against LayerZero

Evercrest Technologies, the entity behind KelpDAO, filed a suit in British Columbia against LayerZero Labs, its Canadian affiliate, and CEO Bryan Pellegrino. The complaint alleges negligent misrepresentation, negligence, and defamation, seeking aggravated and punitive damages. Evercrest asserts that LayerZero had reviewed and endorsed the one-verifier configuration in writing and that it warned another developer about the same risk while withholding a similar warning from Kelp. LayerZero counters that Kelp chose the configuration after previously using a two-of-two setup and that the provider’s role was limited to operating the RPC infrastructure.

Massive asset migrations

Following the exploit, the market reacted quickly. By early August, projects tied to approximately $14.5 billion announced they would move from LayerZero to Chainlink’s Cross-Chain Interoperability Protocol (CCIP). BitGo led the shift, designating CCIP as the exclusive cross-chain solution for its Wrapped Bitcoin (WBTC) holdings, which alone account for about $7.4 billion of the announced migrations. Other participants, including Mantle, Lombard, and Wyoming’s Stable Token Commission, also redirected billions of dollars to CCIP. The total announced migration represents nearly fifty times the value stolen in the rsETH incident.

LayerZero’s security overhaul

In response to the breach and the subsequent exodus, LayerZero revised its default security posture. The protocol now enforces a minimum of three independent verifiers for any bridge that relies on its service, and it refuses to sign messages on channels where it is the sole required signer. Additionally, the company requires multiple RPC sources across different providers and geographic locations. These changes aim to prevent a repeat of the single-point-of-failure scenario that enabled the rsETH loss.

Broader implications for cross-chain infrastructure

The lawsuit highlights a growing tension between self-service protocol providers and the applications that configure them. When a provider both reviews a client’s architecture and operates a critical component, liability may extend beyond the end-user’s choices. Should the court find LayerZero responsible for endorsing the risky setup, providers could face higher insurance costs, demand indemnities, or limit support for custom configurations. Conversely, a ruling that places full responsibility on the application developer would reinforce the current model of configurable, user-driven security.

Why it matters

The dispute and the swift migration of tens of billions of dollars underscore the fragility of cross-chain bridges and the importance of default-by-secure designs. As institutional participants seek more robust guarantees, providers may need to shift from permissive tooling toward enforced safeguards, reshaping the economics and risk profile of the broader decentralized finance ecosystem.