Breaking
GLOBALRepublic of Ireland to play Nations League match against Israel following players' meetingDECrowds at the Oktoberfest: The city advises people not to come to Theresienwiese anymoreGLOBALFederal jury awards Taction Technology $5.7 billion in patent infringement case against AppleRUTrump announced discussions on Patriot missiles with ZelenskyDEForeign ministers meet on the sidelines of the UN general debateDEReichsbürger meeting in Darmstadt: Significantly more counter-demonstratorsRUAn air raid alert has been declared in Kyiv and a number of regions of UkraineTRStatement from Minister of Justice Gürlek on fund investigation: Assets were frozenTRUS President Trump's rejection of Iran's ceasefire offer and foreign policy statementsDEPolitical explorations and debates after state elections in GermanyGLOBALRepublic of Ireland to play Nations League match against Israel following players' meetingDECrowds at the Oktoberfest: The city advises people not to come to Theresienwiese anymoreGLOBALFederal jury awards Taction Technology $5.7 billion in patent infringement case against AppleRUTrump announced discussions on Patriot missiles with ZelenskyDEForeign ministers meet on the sidelines of the UN general debateDEReichsbürger meeting in Darmstadt: Significantly more counter-demonstratorsRUAn air raid alert has been declared in Kyiv and a number of regions of UkraineTRStatement from Minister of Justice Gürlek on fund investigation: Assets were frozenTRUS President Trump's rejection of Iran's ceasefire offer and foreign policy statementsDEPolitical explorations and debates after state elections in Germany
BackEvercrest Technologies Sues LayerZero Labs Over $292 Million rsETH Exploit
Evercrest Technologies Sues LayerZero Labs Over $292 Million rsETH Exploit
NEWS
CryptoSlate1 hour agoBusiness5 min read

Evercrest Technologies Sues LayerZero Labs Over $292 Million rsETH Exploit

Lawsuit in British Columbia alleges negligence and misrepresentation following April security breach

Quick Look

  • Evercrest Technologies, developer of KelpDAO, has filed a lawsuit against LayerZero Labs and CEO Bryan Pellegrino in British Columbia, alleging negligence regarding an April $292 million rsETH exploit.
  • The case centers on disputed liability for bridge security configurations.

AI-generated summary

Why It Matters

In April, a security breach involving LayerZero's infrastructure resulted in the theft of $292 million in rsETH from the Kelp bridge. The incident involved social engineering of a developer and the poisoning of internal RPC nodes.

Font size

Evercrest Technologies, the company behind KelpDAO, has sued LayerZero Labs, its Canadian affiliate, and CEO Bryan Pellegrino in British Columbia over April's $292 million rsETH exploit.

The claim alleges negligent misrepresentation, negligence and defamation, seeks aggravated and punitive damages, and says Kelp users have withdrawn more than $650 million since the attack.

Pellegrino has called the suit meritless. By Aug. 4, projects tied to roughly $14.5 billion in assets had announced moves from LayerZero to Chainlink's CCIP, nearly 50 times the amount stolen.

The lawsuit now asks a court to settle a responsibility dispute that customers have been pricing on their own since April.

Two failures had to line up

On April 18, attackers tricked LayerZero's verifier into approving a forged cross-chain transfer. LayerZero's incident report traces the intrusion to a developer who was socially engineered into cloning a malicious GitHub repository in March.

The attackers reached LayerZero's RPC environment, poisoned two internal nodes, and knocked an external RPC provider offline, so the verifier signed a message built on false source-chain data and 116,500 rsETH left Kelp's bridge.

That compromise succeeded because Kelp's bridge required approval from a single verifier, LayerZero's own, leaving one party able to authorize the release. The on-chain signature check worked as designed, since the signature was valid and simply attested to false information.

LayerZero's report splits the blame accordingly, assigning the number of required verifiers to the application and the compromised RPC layer to LayerZero as its operator.

Kelp's claim targets what happened to LayerZero before the hack

Evercrest alleges LayerZero reviewed and approved the single-verifier setup in writing, including telling Kelp in February 2024 there was “no problem” with a default configuration.

The suit also alleges LayerZero warned another developer, USDT0, about risks in default verifier configurations while withholding a comparable warning from Kelp.

Those allegations have yet to be tested in court. LayerZero's account puts the choice on Kelp, saying the application had previously used a two-of-two configuration and moved to one-of-one.

LayerZero's verifier now refuses to sign on any channel where it's the only required signer, and the company requires multiple independent RPC sources across providers and geographies.

By Aug. 4, it had moved default pathways on both versions of its endpoint to a minimum of three verifiers, while applications can still build custom setups at the protocol level.

LayerZero also said in May that letting its own verifier act alone on high-value transfers had been a mistake, and it maintained the incident touched about 0.14% of the applications on its network.

LayerZero customers moved faster than the courts

BitGo accounted for the largest migration, with WBTC making up about $7.4 billion of the Aug. 4 tally, and it named CCIP its exclusive cross-chain provider for WBTC and the default for future BitGo-issued assets.

Mantle, Kelp's rsETH and Lombard added billions more, and Chainlink puts the total near $15 billion. Kelp says its own migration remains underway, so announced value and completed transfers are separate measures.

Wyoming's Stable Token Commission fully moved its FRNT state-issued token off LayerZero in August and signed a multi-year deal making CCIP its exclusive cross-chain provider.

Commission CISO Keith Lawhorn said Sept. 14 that the review began because of the Kelp attack and found problems with access controls, private key management, and incident disclosures, findings LayerZero has partly disputed.

The standard he described was infrastructure that is secure by default, with safeguards built into the product for a public issuer to rely on.

A responsibility gap that reaches past bridges

Kelp chose how many verifiers its bridge required, and LayerZero ran the infrastructure its only verifier depended on. Each party controlled a layer that failed, and the smart contract accepted the configuration both had allowed.

The same arrangement appears wherever an automated protocol depends on an identifiable company for oracles, custody, cloud hosting, or sequencing, since smart contracts turn whatever those services attest into irreversible outcomes.

A self-service provider can argue that a customer picked its own settings from the tools on offer. Kelp's allegation describes a provider that reviewed a client's architecture, called it acceptable, and operated the component that later broke, a harder position to defend if the allegations hold up.

LayerZero remains a large network, spanning 96 chains and $9.5 billion in bridged volume for the past 30 days, according to DefiLlama.

If the court and the contracts behind the integration place responsibility for verifier choices on the application owner, configurable infrastructure keeps its place, with providers adding formal risk acknowledgments and hardened defaults like LayerZero's.

The migration wave would settle into a one-time repricing, and LayerZero's message volume and new asset launches would show whether its redesign restored confidence.

If Kelp substantiates its written-approval claims, approving custom security designs starts carrying legal exposure. Vendors could respond with warranties, indemnities and higher prices, or by refusing to sign off on nonstandard configurations.

More issuers adopting Wyoming's secure-by-default standard would steer institutional assets toward a smaller group of approved providers, trading configuration risk for concentration risk.

Kelp's bridge did exactly what its configuration told it to do, and LayerZero's verifier signed exactly what its compromised infrastructure told it was true. A court in British Columbia will now decide who owed the safeguards the industry spent five months adding.

What to Watch

AI outlook — possibilities, not facts

  • The court will determine liability for the verifier configuration choices.

    Possible · Within months

Open Questions

  • Will the court find LayerZero liable for the configuration approval?
  • How will the lawsuit impact future cross-chain bridge liability standards?

Related Topics

This article was originally published by CryptoSlate.

Related Stories

European Banking Authority urges European Commission to review MiCA rules for crypto firms facilitating DeFi lending
Developing·

European Banking Authority urges European Commission to review MiCA rules for crypto firms facilitating DeFi lending

The European Banking Authority has requested the European Commission to conduct a cost-benefit analysis of potential regulatory duties for crypto-asset service providers that facilitate customer access to decentralized finance lending protocols, citing consumer risks such as inadequate disclosures, leverage dangers, and lack of creditworthiness checks, with the Commission’s consultation closing on September 30.

CryptoSlate
2 min read
Bitget reports $387.5 million in assets stolen in Sept. 24 wallet breach, withdrawals suspended
BREAKING·

Bitget reports $387.5 million in assets stolen in Sept. 24 wallet breach, withdrawals suspended

Bitget reported that approximately $387.5 million in assets were transferred to attacker-controlled addresses during a wallet breach on Sept. 24, with withdrawals suspended through Sept. 25 while deposits and trading continued. The exchange cited its User Protection Fund as covering the loss and noted collaboration with Mandiant and SlowMist. Syngnum announced an alternative custody solution for institutional clients on the same day, allowing trading using collateral held at the Swiss bank, though details on client uptake and whether any protected assets were affected remain undisclosed.

CryptoSlate
2 min read
More on this topickelpdao