Evercrest Technologies, the development entity behind the liquid restaking protocol KelpDAO, has initiated legal proceedings against LayerZero Labs and its Canadian affiliate. The lawsuit, filed in British Columbia, also names LayerZero CEO Bryan Pellegrino as a defendant. The legal action stems from a significant security breach that occurred in April, resulting in the loss of approximately $292 million in digital assets.
The complaint includes allegations of negligence, negligent misrepresentation, and defamation. Evercrest Technologies is seeking both aggravated and punitive damages, claiming that the infrastructure provider failed to maintain the security standards expected of a cross-chain interoperability service. This case represents a significant moment in the decentralized finance (DeFi) sector, as it seeks to establish legal accountability for infrastructure providers during security failures.
The core of the dispute involves the exploit of rsETH, a liquid restaking token managed by KelpDAO. The incident has already triggered a massive shift in the market, with several high-profile projects moving their assets to alternative interoperability solutions. As the legal process begins, the industry is closely watching how the courts will interpret the responsibilities of protocol developers versus infrastructure providers.
Key Points of the Dispute
- Evercrest Technologies alleges that LayerZero Labs was negligent in its security practices, leading to a $292 million exploit of rsETH in April 2024.
- The lawsuit claims that LayerZero provided written approval for a security configuration that utilized only a single verifier, which the attackers eventually compromised.
- Following the exploit, approximately $14.5 billion in assets have migrated from LayerZero to Chainlink’s Cross-Chain Interoperability Protocol (CCIP).
- LayerZero CEO Bryan Pellegrino has dismissed the lawsuit as meritless, while the protocol has since updated its default security requirements to include multiple verifiers.
The Mechanics of the $292 Million rsETH Exploit
The security breach that prompted this lawsuit occurred on April 18, but the groundwork for the attack was laid weeks earlier. According to technical post-mortems and the legal filings, the exploit began with a sophisticated social engineering campaign targeting a developer in March. The attackers successfully convinced the developer to clone a malicious GitHub repository, which allowed them to gain unauthorized access to internal systems.
Once inside the environment, the attackers were able to poison LayerZero’s internal Remote Procedure Call (RPC) nodes. These nodes are critical components that allow different parts of a blockchain network to communicate. By compromising these nodes, the attackers were able to manipulate the data being sent to LayerZero’s verifier, the entity responsible for authorizing cross-chain transactions.
The attackers successfully tricked the verifier into signing a forged cross-chain transfer. This allowed them to drain 116,500 rsETH from the protocol. Because the system recognized the signature as valid, the transfer was processed without further scrutiny. The scale of the loss, valued at nearly $300 million at the time, sent shockwaves through the restaking ecosystem and raised immediate questions about the robustness of the underlying infrastructure.
Allegations of Negligence and Misrepresentation
A central point of contention in the Evercrest lawsuit is the specific configuration of KelpDAO’s bridge at the time of the attack. The legal claim states that the bridge was set up to require only a single verifier—LayerZero’s own internal verifier—to authorize transfers. In many DeFi configurations, multiple independent verifiers are used to provide a layer of redundancy and security, ensuring that no single point of failure can lead to a total loss of funds.
Evercrest Technologies alleges that this single-verifier setup was not an oversight by the KelpDAO team but was instead a configuration reviewed and approved by LayerZero. The lawsuit claims that LayerZero provided written confirmation in February 2024 that the architecture was appropriate for the protocol’s needs. Evercrest argues that this constitutes negligent misrepresentation, as they relied on LayerZero’s expertise to ensure the safety of the bridge.
Furthermore, the lawsuit includes claims of defamation against Bryan Pellegrino. While the specific statements are not detailed in the summary of the filing, the inclusion of such charges suggests a breakdown in professional relations following the exploit. For his part, Pellegrino has publicly characterized the legal action as meritless, suggesting that the responsibility for the configuration and its subsequent failure may lie elsewhere.
Industry Fallout and the Shift to Chainlink CCIP
The impact of the exploit extended far beyond the immediate loss of rsETH. In the months following the incident, a significant number of decentralized applications and asset issuers began to re-evaluate their reliance on LayerZero’s infrastructure. This has resulted in a massive migration of capital toward Chainlink’s Cross-Chain Interoperability Protocol (CCIP), which has positioned itself as a more secure alternative.
Data indicates that projects representing approximately $14.5 billion in assets have announced or completed migrations to Chainlink CCIP since the April exploit. One of the most notable moves came from BitGo, which transitioned $7.4 billion in Wrapped Bitcoin (WBTC) to CCIP. BitGo designated Chainlink as the exclusive cross-chain provider for the asset, citing the need for enhanced security and reliability.
Other entities have followed suit, including Wyoming’s Stable Token Commission. The commission moved its FRNT token off LayerZero following a comprehensive security review. The review reportedly cited specific concerns regarding access controls and the management of private keys within the LayerZero ecosystem. These migrations suggest that the market is placing an increasing premium on security over ease of integration in the wake of the KelpDAO incident.
Defining the Responsibility Gap in DeFi Infrastructure
The lawsuit between Evercrest and LayerZero highlights what many industry observers call a “responsibility gap” in the decentralized finance sector. This gap refers to the ambiguity regarding who is at fault when a security failure occurs: the infrastructure provider that offers the tools, or the application developer who chooses how to implement those tools.
LayerZero has argued that its protocol is a permissionless toolset and that developers are responsible for their own security configurations. However, the claim that LayerZero provided “guided integration” and written approval for the KelpDAO setup complicates this defense. If a service provider takes an active role in reviewing and approving a customer’s security architecture, they may take on a higher level of legal liability.
In response to the incident, LayerZero has implemented significant changes to its security model. The protocol now requires a minimum of three verifiers for its default pathways and has stated that it will no longer act as the sole signer on any channel. While these changes aim to prevent similar exploits in the future, they also serve as a tacit acknowledgment that the previous default configurations may have carried inherent risks. Despite the scale of the rsETH loss, LayerZero noted that the exploit affected only about 0.14% of the applications currently utilizing its network.
What Happens Next
The legal proceedings in British Columbia are expected to be a lengthy process as both sides present evidence regarding the technical communications and agreements made prior to the February 2024 approval. The court will likely focus on the nature of the “written approval” cited by Evercrest and whether it constitutes a binding guarantee of security or a mere technical review.
The outcome of this case could set a major precedent for the crypto industry. If Evercrest is successful, it may force other infrastructure providers to adopt more rigorous legal and technical standards when assisting clients with integrations. Conversely, a victory for LayerZero could reinforce the “buyer beware” nature of permissionless protocols, placing the entirety of the security burden on the application developers.
Meanwhile, the competition between cross-chain protocols is expected to intensify. As Chainlink CCIP continues to capture market share from former LayerZero users, other interoperability solutions may also see increased interest. The industry’s focus is shifting toward multi-signature requirements and decentralized verification methods as the standard for protecting large-scale asset transfers across different blockchain networks.
