Evercrest Technologies, the company behind KelpDAO, has filed a lawsuit against LayerZero Labs and CEO Bryan Pellegrino in British Columbia over a $292 million exploit that occurred in April. The claim alleges negligent misrepresentation, negligence, and defamation, and seeks aggravated and punitive damages.
According to Evercrest, Kelp users have withdrawn more than $650 million since the attack. LayerZero Labs has called the suit meritless.
How the Attack Unfolded
On April 18, attackers tricked LayerZero's verifier into approving a forged cross-chain transfer. LayerZero's incident report traces the intrusion to a developer who was socially engineered into cloning a malicious GitHub repository in March.
The attackers reached LayerZero's RPC environment, poisoned two internal nodes, and knocked an external RPC provider offline. This allowed the verifier to sign a message built on false source-chain data, and 116,500 rsETH left Kelp's bridge.
The compromise succeeded because Kelp's bridge required approval from only a single verifier—LayerZero's own—leaving one party able to authorize the release.
The Lawsuit's Core Claim
Evercrest alleges that LayerZero reviewed and approved the single-verifier setup in writing, including telling Kelp in February 2024 there was "no problem" with the default configuration. The suit also alleges LayerZero warned another developer about risks in default verifier configurations while withholding a comparable warning from Kelp.
LayerZero's account places the choice on Kelp, saying the application had previously used a two-of-two configuration and moved to one-of-one.
Industry Response
By August 4, projects tied to roughly $14.5 billion in assets had announced moves from LayerZero to Chainlink's CCIP—nearly 50 times the amount stolen in the exploit.
BitGo accounted for the largest migration, with WBTC making up about $7.4 billion of the total. Mantle, Kelp's rsETH, and Lombard added billions more. Wyoming's Stable Token Commission fully moved its FRNT state-issued token off LayerZero in August and signed a multi-year deal making CCIP its exclusive cross-chain provider.
LayerZero's Changes
LayerZero's verifier now refuses to sign on any channel where it is the only required signer. The company requires multiple independent RPC sources across providers and geographies, and by August 4 had moved default pathways on both versions of its endpoint to a minimum of three verifiers.
LayerZero said in May that allowing its own verifier to act alone on high-value transfers had been a mistake. The company maintained the incident touched about 0.14 percent of the applications on its network.
LayerZero remains a large network, spanning 96 chains with $9.5 billion in bridged volume for the 30 days preceding the reporting date, according to DefiLlama.


