Evercrest Technologies, the company behind KelpDAO, filed a civil claim against LayerZero Labs Ltd., LayerZero Labs Canada Inc., and co-founder Bryan Pellegrino in the Supreme Court of British Columbia on Wednesday. The lawsuit alleges negligent misrepresentation, negligence, and defamation stemming from the $292 million exploit that occurred in April.
According to the filing, KelpDAO's bridges operated using a 1-of-1 setup, meaning LayerZero's own verifier network was the sole party confirming that tokens had been locked on one chain before equivalent tokens were minted on another. Evercrest claims LayerZero explicitly directed it to use this configuration. LayerZero told Evercrest in February 2024 that its draft code was "good" with "[n]o problem" using the default configuration, and in March 2024 explicitly directed the company to use a 1-of-1 setup with LayerZero's verifier, according to the filing.
The exploit began inside LayerZero's infrastructure. On March 6, an attacker placed malware on a LayerZero developer's computer and tampered with LayerZero's nodes to feed false readings to its verifier. On April 18, the attacker disabled third-party nodes the verifier also relied on, causing it to be told that 116,500 rsETH had been locked on Unichain when nothing had. With only one verifier required, the tokens were minted without backing. Evercrest says it paused the bridges within approximately one hour and blocked a second attempt.
The filing notes that LayerZero warned a separate developer, USDT0, about risks in its default verifier configurations in late 2024 or early 2025, prompting that developer to run its own verifier. Evercrest says it received no comparable warning.
Following the exploit, defamation issues emerged from LayerZero's public statements. LayerZero's incident statement said the single-verifier setup contradicted a multi-DVN model it had "consistently recommended to all integration partners." Co-founder Pellegrino stated that "[n]obody should be relying on sole DVN." Days later, LayerZero admitted it had "made a mistake by allowing [its] DVN to act as a 1-of-1 DVN for high-value transactions."
Evercrest claims damages including a 2,000 ETH contribution to restore rsETH's backing, more than $650 million withdrawn since the exploit, and a decline in the KERNEL token that drew regulator and exchange warnings.
Pellegrino tweeted that the claim "continues to be meritless" and stated he would meet Evercrest in Vancouver to defend himself. None of the allegations has been tested in court, and no response to the claim has been filed.


