BLOCKCHAIN AI.NEWS

Policy

'No Problem': Kelp Takes LayerZero's 2024 Answer to a Vancouver Court

Evercrest, the company behind KelpDAO, has sued LayerZero and its CEO in British Columbia over April's $292 million rsETH exploit. Its case leans on two things: what LayerZero allegedly told it in 2024, and what LayerZero admitted in May.

Editorial illustration: a single frosted glass gate stands alone on a chrome bridge beside a blue-lit rail, with a gold-lit sealed envelope on a chrome lectern in the foreground
✓ Filing first announced by Bryan Pellegrino on X, then by KelpDAO · Details of the claim via The Block, Decrypt, The Crypto Times and CoinDesk · Incident record from LayerZero's April statement and May report

The first public word of the lawsuit came from the man being sued. At 22:57 UTC on September 24, LayerZero co-founder and CEO Bryan Pellegrino posted that "Evercrest (KelpDAO) filed a notice of civil claim today in BC against myself and LZ." He added: "The claim continues to be meritless, will meet them in Vancouver and defend myself accordingly."

Five hours later KelpDAO published its own statement. The suit, it said, was meant "to right the wrongs associated with the exploit of rsETH's LayerZero bridge earlier this year." Its core claim is one sentence: "LayerZero reviewed and endorsed—in writing—our deployment and configuration of LayerZero's technology."

The claim was filed in the Supreme Court of British Columbia. The Crypto Times gives the Vancouver registry file number as 267169. The plaintiff is Evercrest Technologies. According to The Block and Decrypt, the defendants are LayerZero Labs Ltd., LayerZero Labs Canada Inc. and Pellegrino personally, and the causes of action are negligent misrepresentation, negligence and defamation. KelpDAO says the complaint is public, and outlets have linked a copy, but the copy was not downloadable when the Desk tried. Everything below about what the filing says comes from outlets that read it, and none of it has been tested in court.

What happened in April

The exploit itself is well documented. Kelp's rsETH, a liquid restaking token, moved between chains over LayerZero. Each app on LayerZero picks its own decentralized verifier networks, or DVNs, which attest that a cross-chain message is real. LayerZero's April 19 statement said Kelp's setup "relied on a 1-of-1 DVN setup, with LayerZero Labs as the sole verifier."

LayerZero's May 20 incident report explains how that single verifier was fooled. On March 6 an attacker social-engineered a LayerZero Labs developer and got into the RPC environment the company's DVN read from. On April 18 a forged message went through. "Because no second independent DVN was required to attest," the report says, "the destination contract accepted the single valid attestation and unlocked rsETH." That was 116,500 rsETH, about $292 million. The report says Mandiant, CrowdStrike and independent researchers attribute the attack to the North Korean group TraderTraitor, also tracked as UNC4899.

The Crypto Times puts the drain at 17:35 UTC and the freeze of Kelp's core contracts at 18:21 UTC, 46 minutes later, which blocked two more attempts worth $95 million to $100 million. CoinDesk's report on the lawsuit dates the exploit to April 22. LayerZero's own documents and the other outlets say April 18, and the Desk uses that date.

Two stories, one configuration

DateEventSource
Feb 2, 2024LayerZero allegedly says there is "no problem" using the default configurationClaim, per The Block
Mar 21, 2024LayerZero allegedly directs Evercrest to copy another bridge's 1-of-1 setupClaim, per The Block
Mar 6, 2026LayerZero Labs developer social-engineeredLayerZero report
Apr 18, 2026116,500 rsETH released on a forged messageLayerZero report
Apr 19, 2026LayerZero says it had told Kelp to diversify verifiersLayerZero statement
May 5, 2026Kelp publishes Telegram screenshotsCoinDesk
May 9, 2026LayerZero: "we made a mistake"CoinDesk
Sep 24, 2026Notice of civil claim filed in VancouverPellegrino, The Crypto Times
Sources: The Block, LayerZero incident report, LayerZero statement, CoinDesk, May 5, CoinDesk, May 9. The 2024 entries are allegations in the claim and have not been tested.

The argument has been public since April

The lawsuit is new. The dispute behind it isn't. LayerZero's first statement blamed the configuration: "LayerZero and other external parties previously communicated best practices around DVN diversification to KelpDAO," it said, calling the incident "isolated entirely to KelpDAO's rsETH configuration."

Kelp responded in May with Telegram screenshots, reported by CoinDesk, which it said showed LayerZero staff aware of its verifier setup across eight integration discussions over two and a half years. One message read: "No problem on using defaults either." LayerZero's position was that Kelp had "deployed multiDVN and then manually downgraded to a 1/1," and that a single verifier appearing in its templates pointed to a placeholder "DeadDVN" contract that had to be configured before use. CoinDesk also reported that 47 percent of LayerZero app contracts had used 1-of-1 setups over the 90 days before the exploit.

Four days later LayerZero changed its tone. "We made a mistake by allowing our DVN to act as a 1/1 DVN for high-value transactions," it said, per CoinDesk, adding "We own that." Its DVN stopped serving single-verifier setups, and defaults moved to five verifiers where possible, with a floor of three. The May report went further: LayerZero "has historically been un-opinionated toward OApp builders" about security configuration, and that stance "has changed." Kelp, meanwhile, moved rsETH's bridge to Chainlink's CCIP.

What the claim adds

According to The Block, the filing states that "the exploit was not a failure of KelpDAO's systems. It was a failure of LayerZero's own security infrastructure." It dates the "no problem" exchange to February 2, 2024, and alleges that on March 21, 2024, LayerZero told Evercrest to use the same 1-of-1 configuration as another bridge. It says LayerZero described its DVN as having redundancy across multiple locations with monitoring and alerts, and that the worst a compromised DVN could do was "fail to verify a message correctly." That last point matters because the April attack did the opposite: it made the verifier approve a false message.

The claim also points to another customer. It says LayerZero warned USDT0 about the risks of default DVN configurations before the exploit. Decrypt reports the warning came in late 2024 or early 2025 and led that team to run its own verification. No comparable warning, the claim says, went to Evercrest. Decrypt also quotes Pellegrino, as cited in the claim: "[n]obody should be relying on sole DVN." None of the reports the Desk read says which of his public statements the defamation count is based on.

Reports of the damages sought don't match. CoinDesk puts the figure at $292 million. The Block describes compensatory, aggravated and punitive damages without a total, and notes that users have withdrawn more than $650 million since the exploit and that Kelp's sbUSD product was shut down. Decrypt lists the 2,000 ETH Evercrest contributed to restore rsETH's backing and the fall in its KERNEL token. The Crypto Times says it could not verify the relief sought. The Desk hasn't read the filing, so it can't settle the question.

What happens next

A notice of civil claim in British Columbia is the start of a case, not a finding. The defendants have a set period to respond once served, and nothing in the claim has been proven. Pellegrino has said how he will respond. Neither side has said whether it would consider settling.

The Take

Both sides have a point. Kelp ran a $292 million bridge on one verifier, and a protocol that says "configure your own security" is not obviously liable when a customer configures it thinly. But LayerZero also operated the one verifier, and its own infrastructure was the part that got compromised. It then said in writing that letting that verifier stand alone for high-value transfers was its mistake. The court now has to decide whether "no problem on using defaults" was advice or small talk. The industry already has its answer. When 47 percent of apps were running on a single verifier, those defaults were effectively recommendations, whatever the documentation said.

More on the subject