Evercrest Technologies, the entity associated with KelpDAO, has sued LayerZero and CEO Bryan Pellegrino in British Columbia over an April rsETH bridge exploit that resulted in losses of approximately $292 million. The civil claim escalates a months-long dispute between the parties regarding responsibility for the attack and LayerZero's security disclosures.
KelpDAO alleges that LayerZero failed to adequately disclose security risks associated with its bridge technology before the April 18 attack. According to the complaint, LayerZero had reviewed and approved KelpDAO's bridge deployment and configuration in writing. Pellegrino has called the claims "meritless" and stated he plans to defend the case in Vancouver.
Attack Details and Technical Disagreement
The April attack began after an attacker socially engineered a LayerZero developer to obtain session credentials, then accessed LayerZero's RPC cloud environment and compromised internal nodes. The compromised nodes supplied false blockchain information to LayerZero's Decentralized Verifier Network, while a denial-of-service attack disrupted an external RPC provider used by the verification system.
KelpDAO's rsETH bridge employed a 1-of-1 DVN configuration, allowing a single verifier to approve cross-chain messages. The compromised verifier approved a message claiming rsETH had been burned on another chain, prompting the Ethereum-side contract to release 116,500 rsETH to the attacker despite no corresponding burn occurring.
LayerZero argues that KelpDAO's single-verifier design created the critical failure point and claims it had recommended stronger configurations. KelpDAO disputes this position and maintains that LayerZero approved its bridge setup.
Attribution and Ongoing Actions
LayerZero's investigation attributed the operation to TraderTraitor, a threat group associated with North Korea's Lazarus Group, with independent researchers reaching the same conclusion. Authorities and ecosystem participants have frozen portions of assets linked to the attacker following the breach.
KelpDAO has begun migrating rsETH cross-chain transfers to a different security framework, having previously identified Chainlink CCIP as a replacement for its LayerZero-based bridge. The court has not yet determined responsibility for the exploit, with legal proceedings ongoing in British Columbia.


