Skip to content

Invest4 publishers3 min readPublished

KelpDAO's developer sues LayerZero over the lone-verifier setup behind the $292 million rsETH exploit

Evercrest, the company behind KelpDAO, is suing LayerZero and CEO Bryan Pellegrino in British Columbia over the $292 million rsETH bridge exploit. Its negligence case rests on written 2024 assurances about a single verifier and on a risk warning it says LayerZero gave another customer.

The Investor · Invest desk

Photograph accompanying KelpDAO's developer sues LayerZero over the lone-verifier setup behind the $292 million rsETH exploit
Photo: unchainedcrypto.com

What happened

  • Evercrest Technologies, the company behind KelpDAO, sued LayerZero Labs, its Canadian arm and co-founder Bryan Pellegrino in British Columbia for negligent misrepresentation, negligence and defamation.
  • The April 18 exploit took 116,500 rsETH, worth about $292 million, from a bridge where LayerZero's own verifier was the only one required to approve a mint.
  • Evercrest alleges LayerZero told it in February 2024 that the default setting presented no problem, then told it in March 2024 to clone another bridge's 1-of-1 setup.
  • Pellegrino wrote that the claim "continues to be meritless" and said he would meet Evercrest in Vancouver to defend himself.

Compiled by The InvestorSomething wrong?How this is made

Why it matters

  • cost Kelp's outflows are larger than the theft: more than $650 million withdrawn since April is about 2.2 times the value taken, and Evercrest is claiming that larger sum from LayerZero.
  • exposure Cryptopolitan put 47% of active LayerZero app contracts on 1-of-1 at the time of the exploit, so any written sign-offs LayerZero gave those teams would support the same kind of claim.
  • contradiction LayerZero blamed Kelp for leaving a multi-DVN model it had "consistently recommended to all integration partners," yet the filing says LayerZero later admitted it "made a mistake" letting its DVN act as a 1-of-1.
  • precedent A finding for Evercrest on the USDT0 warning would oblige a vendor that advises many integrators to give each of them the same risk notice.

Since April, Kelp has spent its money on repairs and replacement. Its damages list includes a 2,000 ETH contribution to restore rsETH's backing [11], about 1.7% of the unbacked tokens by count [4]. It has shut down its planned sbUSD stablecoin and picked Chainlink's CCIP to carry rsETH in LayerZero's place [12]. According to the filing, the fall in the KERNEL token drew warnings from regulators and exchanges [11].

Cointelegraph describes the months-long fight as a question of whether the loss came from LayerZero's compromised infrastructure, Kelp's bridge configuration, or both [22]. The filing starts with the first. On Evercrest's account, malware went onto a LayerZero developer's computer on March 6, and the attacker then tampered with LayerZero's nodes so they fed false readings to its verifier [9]. On April 18 the attacker disabled the third-party nodes the verifier also used, and the verifier was told 116,500 rsETH had been locked on Unichain when nothing had [9]. That puts 43 days between the malware and the mint [3]. The filing quotes LayerZero's January 2025 pitch, which said a compromised verifier could at most "fail to verify a message correctly" [7]. This one approved a false message, and tokens worth about $2,506 apiece at the time were minted against it [1].

LayerZero's final incident report accepts that its internal nodes were compromised. It argues the forged message cleared only because Kelp's bridge relied on a single DVN as its only verification path [13]. Pellegrino said in May that Kelp's account was "completely untrue," and that Kelp had launched on LayerZero's multi-DVN default and switched to 1-of-1 itself [16]. Kelp, for its part, wrote that it needs to "correct the record, and hold LayerZero and Mr. Pellegrino accountable for the harm they have caused us and the broader DeFi ecosystem" [20].

In my view the allegation with the most reach is a different one. According to the filing, LayerZero warned the developer of USDT0 about the risks of default verifier setups in late 2024 or early 2025, and that developer went on to run its own verifier [8]. Evercrest says Kelp got no comparable warning [8]. This allegation matters whichever side flipped Kelp's setting. It goes to what LayerZero knew before April and which customers it told.

If the court treats LayerZero's 2024 messages as advice Kelp was entitled to rely on, configuration risk moves toward the vendor. If it accepts Pellegrino's version [16], the risk stays with the customer, where LayerZero's report puts it [13]. A settlement would leave neither answer on the record. I'd expect the USDT0 allegation to decide how far the negligence count gets. That view fails if LayerZero produces a warning sent to Kelp like the one USDT0 received. None of the allegations has been tested in court, and no response has been filed [19]. So far, Kelp's own move to CCIP is the only change of vendor the record shows [12].

What to watch

  • LayerZero's response to the notice of civil claim, and whether it disputes the February and March 2024 messages or the USDT0 warning.
  • Whether other teams from LayerZero's former 1-of-1 integrations disclose similar written sign-offs or file claims of their own.
  • Completion of Kelp's rsETH migration to Chainlink's CCIP, and whether withdrawals keep running after the move.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories