Evercrest Technologies, the firm behind KelpDAO, has initiated legal action in British Columbia against LayerZero Labs, its Canadian affiliate, and CEO Bryan Pellegrino following an April 18 security breach that drained $292 million in rsETH. The suit, which alleges negligence, negligent misrepresentation, and defamation while seeking aggravated and punitive damages, comes as Kelp users have withdrawn over $650 million since the incident.
Architecture Failure and Contested Blame
The exploit occurred after attackers socially engineered a LayerZero developer in March into cloning a malicious GitHub repository. The perpetrators gained access to LayerZero’s RPC infrastructure, poisoned two internal nodes, and knocked an external RPC provider offline. Consequently, LayerZero’s verifier signed forged cross-chain messages based on compromised source-chain data, causing 116,500 rsETH to leave Kelp’s bridge.
The exploit succeeded because Kelp’s bridge configuration required validation from only a single verifier—LayerZero’s own. In its claim, Evercrest alleges that LayerZero reviewed and approved this single-verifier setup in writing in February 2024, assuring Kelp there was "no problem" with the default parameters. The lawsuit further alleges that LayerZero warned another project, USDT0, about single-verifier risks while failing to alert Kelp. Pellegrino has dismissed the lawsuit as meritless, maintaining that Kelp previously operated a two-of-two configuration before voluntarily switching to a one-of-one setup.
Following the attack, LayerZero updated its default pathways to require a minimum of three verifiers across both versions of its endpoint. However, the legal dispute, detailed in recent coverage of KelpDAO's lawsuit against LayerZero, highlights ongoing debate over cross-chain security responsibility.
Mass Exodus to Chainlink CCIP
Capital market reactions have moved significantly faster than judicial proceedings. By Aug. 4, projects controlling approximately $14.5 billion in assets announced plans to migrate from LayerZero to Chainlink’s Cross-Chain Interoperability Protocol (CCIP)—a figure nearly 50 times the amount stolen in the exploit.
Major asset issuers and protocols leading the migration include:
- BitGo: Moving $7.4 billion in Wrapped Bitcoin (WBTC), designating CCIP as its exclusive cross-chain provider.
- Wyoming Stable Token Commission: Transitioning its state-issued FRNT token off LayerZero after a review by CISO Keith Lawhorn identified concerns with access controls and key management on Sept. 14.
- Mantle, Lombard, and KelpDAO: Transitioning billions in additional liquidity to CCIP.
Why It Matters
This legal and operational fallout underscores a fundamental friction point in decentralized finance: the gap between application-level smart contract choices and third-party infrastructure reliability. When automated protocols rely on external companies for validation, cloud hosting, or RPC data, software execution turns third-party errors into irreversible losses. As protocols increasingly prioritize "secure by default" cross-chain architecture, infrastructure providers will likely face heightened legal accountability for architectural consulting and node operation.
