
Evercrest Technologies alleges LayerZero endorsed the bridge configuration that led to the massive rsETH exploit.
Evercrest Technologies, the developer behind KelpDAO, has sued LayerZero and CEO Bryan Pellegrino in British Columbia, alleging the protocol's bridge configuration was endorsed by LayerZero before a $292 million exploit occurred in April.
AI-generated summary
The lawsuit follows a $292 million exploit in April involving the restaking protocol KelpDAO. The dispute centers on whether LayerZero provided negligent instructions regarding bridge configurations.
The company behind KelpDAO has sued LayerZero and its chief executive over the exploit that drained $292 million from the restaking protocol in April, alleging LayerZero endorsed in writing the exact bridge configuration it later blamed for the loss.
Evercrest Technologies filed the notice of civil claim in the Supreme Court of British Columbia on Wednesday, naming LayerZero Labs Ltd., LayerZero Labs Canada Inc. and co-founder Bryan Pellegrino, who is sued personally over posts on Telegram and X. It pleads negligent misrepresentation, negligence and defamation, and seeks aggravated and punitive damages.
KelpDAO's bridges ran a 1-of-1 setup, meaning LayerZero's own verifier network was the only party confirming that tokens had been locked on one chain before equivalent tokens were minted on another.
Evercrest says that was LayerZero's instruction. LayerZero told it in February 2024 that its draft code was "good" and that there was "[n]o problem" using the default configuration, according to the filing, and in March 2024 explicitly directed it to use a 1-of-1 setup with LayerZero's own verifier. In January 2025, LayerZero said that even if a verifier were compromised, the most it could do was fail to verify a message correctly.
The filing also says LayerZero warned a separate developer, USDT0, about risks in its default verifier configurations in late 2024 or early 2025, prompting that developer to run its own. Evercrest says it received no comparable warning.
The exploit began inside LayerZero, on the claim's account. An attacker put malware on a LayerZero developer's computer on March 6, then tampered with LayerZero's nodes so they fed false readings to its verifier. On April 18 the attacker disabled the third-party nodes the verifier also used, so it was told 116,500 rsETH had been locked on Unichain when nothing had. With one verifier required, the tokens were minted unbacked. Evercrest says it paused the bridges within about an hour and blocked a second attempt.
The defamation claims turn on what followed. LayerZero's incident statement said the single-verifier setup contradicted a multi-DVN model it had "consistently recommended to all integration partners," and Pellegrino wrote that "[n]obody should be relying on sole DVN." Days later, the filing says, LayerZero admitted it had "made a mistake by allowing [its] DVN to act as a 1-of-1 DVN for high-value transactions."
Evercrest claims damages including a 2,000 ETH contribution to restore rsETH's backing, more than $650 million withdrawn since the exploit, and a fall in the KERNEL token that drew regulator and exchange warnings.
AI outlook — possibilities, not facts
Court proceedings in British Columbia will commence.
Very likely · Within months

Bitget attributes its $351.6 million wallet breach to North Korean hackers, launching investigations with Mandiant and SlowMist while withdrawals remain suspended pending security reviews.

KelpDAO has filed a lawsuit against cross-chain protocol LayerZero and CEO Bryan Pellegrino following a $292 million exploit of its rsETH bridge, alleging security failures and lack of risk disclosure.

Blockchain data firm Bitquery found that $117.7 billion out of a $201.4 billion sample of Solana DEX trades involved circular or botlike activity, challenging the reliability of gross volume as a measure of independent trader demand.

US spot Bitcoin ETFs drew $191 million in net inflows on Thursday, extending a six-session streak past $2.8 billion and lifting the year-to-date total to roughly $787 million as Bitcoin traded near $83,807.

The Federal Reserve has proposed detailed capital, redemption, and reporting requirements for stablecoin issuers under its supervision to implement the GENIUS Act, including tiered operational-risk capital charges, two-business-day redemption timelines, monthly disclosures audited by accounting firms and certified by CEOs and CFOs, and an application process for Fed-supervised banks to issue payment stablecoins via subsidiaries, with public comment open for 60 days.

Bitget suspended withdrawals after detecting unauthorized transfers of approximately $351.6 million from its hot and warm wallets on September 24. CEO Gracy Chen confirmed customer balances remain accurate and losses are covered by the exchange's User Protection Fund, which holds over $464 million. Deposits and trading continue normally while withdrawals remain paused pending a security review. The incident pushes September 2026 crypto losses above $684 million, surpassing April's $646.9 million total.