Evercrest Technologies, the legal entity behind KelpDAO, has filed a civil claim in British Columbia against LayerZero and co-founder Bryan Pellegrino over the April 18 rsETH bridge exploit that resulted in approximately $292 million in losses.
Kelp says the defendants failed to adequately disclose risks in LayerZero’s technology and failed to prevent attackers from compromising infrastructure used to verify cross-chain transactions. The claim also alleges LayerZero had reviewed and approved Kelp’s bridge deployment and configuration in writing before the attack. Those allegations have not been adjudicated.
The legal action follows months of disagreement over a KelpDAO exploit that released 116,500 rsETH from an Ethereum bridge contract without a corresponding burn on the source chain.
LayerZero Infrastructure Was Compromised Before rsETH Release
LayerZero’s final incident report traced the intrusion to March 6, when an attacker socially engineered a LayerZero developer and obtained session credentials.
The attacker later entered LayerZero’s cloud environment and modified internal RPC nodes used by the LayerZero Labs Decentralized Verifier Network. On April 18, external RPC providers were hit with a denial-of-service attack, leaving the verifier dependent on compromised internal nodes that supplied false blockchain state.
The LayerZero Labs DVN then generated a valid attestation for a forged cross-chain message. Kelp’s Ethereum bridge released 116,500 rsETH even though the corresponding source-chain burn had never occurred.
A second forged message targeting another 40,000 rsETH was authenticated but did not execute after Kelp paused the affected contracts. Blockaid independently identified the same 1-of-1 verification path and confirmed that no second verifier was present to reject the false message.
Lawsuit Targets Dispute Over 1-of-1 DVN Setup
LayerZero has maintained that Kelp’s bridge configuration created the decisive single point of failure.
Its April incident statement said rsETH relied on a 1-of-1 DVN configuration, meaning the LayerZero Labs verifier alone could authorize a cross-chain message. LayerZero said it had recommended using multiple independent verifiers and argued that a multi-DVN setup would have prevented one compromised verification path from releasing funds.
Kelp disputes that account. Its civil claim says LayerZero reviewed and endorsed the deployment and configuration before the exploit, placing the question of what LayerZero approved and what security warnings it provided at the center of the case. Pellegrino has called the claim meritless and said he intends to defend the case in Vancouver.
DPRK-Linked TraderTraitor Attributed to Attack
LayerZero’s final investigation said Mandiant, CrowdStrike and independent security researchers attributed the intrusion to TraderTraitor, also tracked as UNC4899, a North Korea-linked threat actor.
Chainalysis separately described the incident as an attack on off-chain verification infrastructure rather than a vulnerability in the rsETH token contract itself. Its investigation found that the LayerZero-operated RPC infrastructure feeding the verifier had been manipulated before the forged message was accepted.
Kelp subsequently moved rsETH to Chainlink CCIP as part of a wider reassessment of its cross-chain security architecture.
The British Columbia civil case now puts the parties’ competing accounts of the bridge configuration, LayerZero’s security disclosures and responsibility for the compromised verification infrastructure before the court.



Be the first to comment