Kelp DAO’s developer files a lawsuit against LayerZero
On September 24, Evercrest Technologies, the company behind the Kelp DAO restaking protocol, filed a civil claim in the Supreme Court of British Columbia, Canada, against LayerZero Labs Ltd., LayerZero Labs Canada Inc. and co-founder and CEO Bryan Pellegrino.
The claim seeks to hold the defendants responsible for losses arising from the April 2026 rsETH bridge exploit. Evercrest also alleges that LayerZero and Pellegrino repeatedly made false statements blaming Kelp DAO in an effort to protect their own reputations. These allegations have not been established by a court, and Pellegrino has rejected the claim as meritless.
According to Evercrest’s account, the company began working with LayerZero in 2023 to integrate its Omnichain Fungible Token (OFT) technology into Kelp DAO. Evercrest says LayerZero’s involvement went beyond supplying technical documentation: it also provided deployment assistance, advised on configuration and remained in contact with the project’s engineering team throughout development.
Communications from 2024 and early 2025 cited in reports on the claim allegedly show that LayerZero considered Kelp DAO’s 1-of-1 Decentralized Verifier Network (DVN) configuration acceptable. Evercrest says LayerZero did not instruct it to adopt multiple independent verifiers or warn it about the associated security risks.
The company further alleges that LayerZero warned another developer about risks involving default DVN configurations before the exploit but did not provide equivalent warnings to Kelp DAO.
After the attack, LayerZero pointed to Kelp DAO’s single-verifier configuration as the reason the forged message could be accepted, saying it had consistently recommended a multi-DVN security model. Evercrest disputes that account, arguing that it conflicts with earlier technical communications in which LayerZero allegedly reviewed and endorsed the configuration.
The claim also alleges that Pellegrino repeatedly blamed Kelp DAO in posts on X and Telegram despite knowing, or being in a position where he should have known, that those statements did not accurately reflect the earlier technical exchanges.
Evercrest points to compromised LayerZero infrastructure
A central argument in Evercrest’s case is that the exploit originated in security infrastructure operated by LayerZero, rather than a compromise of Kelp DAO’s own systems or smart-contract code. LayerZero acknowledges that its RPC infrastructure was compromised, while maintaining that the application’s single-verifier configuration allowed the attack to succeed.
LayerZero’s official incident report states that the breach began on March 6, 2026, when an attacker used social engineering to install malware on a developer’s computer. Stolen session credentials subsequently enabled access to infrastructure used to read blockchain data.
On April 18, the attacker disrupted external RPC services with a denial-of-service attack. This left the DVN’s signing service relying on compromised internal data sources.
The manipulated data caused the verifier to authenticate a forged cross-chain message associated with Unichain. Because the affected bridge required approval from only one DVN, no second independent verifier was needed. The message triggered the unauthorized release of 116,500 rsETH on Ethereum, worth approximately $292 million to $293 million at the time. This was an unauthorized unlocking of tokens, rather than the minting of new rsETH. A 1-of-1 DVN configuration also does not mean that one administrative private key alone controls verification.
According to the account supplied with the original report, Kelp DAO detected the incident within roughly an hour and disabled its LayerZero bridges. The team also reported taking action against the attacker’s address and preventing another attempted withdrawal of approximately 40,000 rsETH. These emergency measures should not be interpreted as the ability to freeze an entire blockchain wallet.
Compensation sought for financial and reputational damage
Evercrest says the exploit forced Kelp DAO to commit substantial resources to incident response and restoring rsETH’s backing, while user withdrawals reduced revenue. The original report also describes a decline in the KERNEL token and disruption to stablecoin development plans as confidence in the project weakened.
Evercrest argues that the financial impact was compounded by LayerZero’s public statements after the attack. Its claim is based on allegations of negligent misrepresentation, negligence and defamation, with Pellegrino personally named over his public comments.
In addition to compensation, Evercrest is seeking aggravated and punitive damages, legal costs and other relief. The estimated value of assets involved in the exploit should not be confused with a fixed amount of damages awarded by a court.
The April 18 attack removed approximately 116,500 rsETH from the bridge without a corresponding legitimate source-chain transaction. The tokens were subsequently used to extract value elsewhere in the market.
The consequences spread across DeFi when the attacker used rsETH as collateral on lending platforms. This created substantial bad-debt exposure on Aave, with estimates varying according to the treatment of the affected rsETH and the recovery assumptions used. The financial and operational consequences of security incidents have also featured in the debate over Balancer’s future.
Following the incident, Kelp DAO announced that it would move rsETH’s cross-chain infrastructure to Chainlink CCIP. Its statement accompanying the lawsuit indicated that the migration was underway.
LayerZero subsequently acknowledged shortcomings in its approach to single-verifier configurations and changed its operating policy. Its own DVN would no longer serve as the sole required verifier on a channel. Evercrest nevertheless argues that the company did not retract or correct earlier statements assigning responsibility to Kelp DAO, prompting it to seek compensation and a legal determination of responsibility.
Pellegrino has disputed the lawsuit and said he intends to defend himself in Vancouver. The parties remain divided over the advice given before the exploit and who should bear responsibility for the resulting losses.
ZRO price over 24 hours. Source: CoinGecko, September 25, 2026, at 3:10 p.m., as cited in the original report.At the time of the September 25 snapshot cited in the original report, ZRO was trading around $1.51, down approximately 2.4% over 24 hours. These figures describe that historical snapshot rather than the current market price.