Evercrest Technologies, the company behind KelpDAO, has filed a civil claim in British Columbia against LayerZero Labs entities and co-founder Bryan Pellegrino over the April exploit involving approximately 116,500 rsETH, valued around $292 million at the time. The Block
Evercrest alleges LayerZero reviewed and endorsed the 1-of-1 decentralized verifier network configuration used by the Unichain bridge that was later exploited. The complaint includes claims of negligent misrepresentation, negligence and defamation. The Block
According to the allegations, LayerZero told Evercrest in 2024 there was no problem with the default configuration and later directed it toward a similar setup. Evercrest further alleges LayerZero had separately warned USDT0 about risks associated with default DVN configurations before the KelpDAO exploit. The Block
LayerZero disputes the allegations. Pellegrino described the claim as meritless and said he intends to defend against it. The assertions therefore remain contested allegations, not established findings. The Block
Evercrest says KelpDAO users have withdrawn more than $650 million since the exploit and that the protocol has begun migrating rsETH to another cross-chain security standard. The Block
TOKEN RECON ASSESSMENT
The litigation could become important well beyond KelpDAO and LayerZero because it tests where responsibility sits when protocols rely on third-party interoperability infrastructure.
The technical facts and communications will matter more than either side’s public narrative.
If a court eventually establishes that an infrastructure provider recommended a configuration while possessing undisclosed knowledge of material risks, that could influence how cross-chain vendors document security recommendations and how protocols conduct independent verification.
For now, those are allegations. The next meaningful intelligence will come from LayerZero’s formal response, discovery and any technical evidence introduced into the case.
Source
The Block: KelpDAO lawsuit against LayerZero over rsETH exploit