Evercrest Technologies, the company behind the KelpDAO restaking protocol, has sued LayerZero Labs and bridge co-founder Bryan Pellegrino. The cause was April's $292 million bridge exploit, which Evercrest calls the largest hack of 2026. The case matters because it is the first court test of who bears responsibility for failures in infrastructure used by dozens of DeFi protocols.
What happened to the KelpDAO bridge in April?
According to CoinDesk, the attack is linked to a hacking group tied to North Korea. Attackers planted malware on a LayerZero developer's computer as early as March 6, then simply waited for six weeks while studying the company's internal network. On April 18 they disabled backup verification nodes and fed false data to the bridge's main verifier (a node that confirms tokens are actually locked on one chain before an equivalent copy is minted on another). That verifier confirmed a lock of 116,500 rsETH (a derivative token from restaking Ethereum that pays holders extra yield) on the Unichain network, even though the tokens never actually moved. At the time of the attack, the bridge held nearly a fifth of that token's entire circulating supply, which is why the scale of the hack stood out even among 2026's other DeFi attacks. On the other side of the bridge, the system minted an equivalent amount with no real backing. Evercrest's team paused the bridge within about an hour and managed to block a second attempt, so the actual losses ended up smaller than they could have been.
Why does Evercrest blame LayerZero?
The KelpDAO bridge ran a "1-of-1" setup, meaning confirmation of a transfer depended on a single verifier controlled by LayerZero itself (the company calls this a DVN). There was no independent check. On most large bridges that number is usually higher than one, meaning confirmation needs several independent parties at once. The lawsuit cites correspondence with LayerZero that, Evercrest argues, shows the company pushed for exactly that configuration.
- In February 2024 LayerZero called Evercrest's draft code "good" and raised no objection to the default settings.
- In March 2024 the company directly recommended using a single-verifier scheme controlled by LayerZero itself.
- In January 2025 LayerZero assured its partner that even a compromised verifier could, at worst, simply fail to confirm a message, and nothing more.
- In late 2024 or early 2025, LayerZero warned a different client, the developer behind USDT0 (a cross-chain wrapper for Tether), about risks in the default configuration. USDT0 switched to running its own verifier. Evercrest says it received no such warning.
What exactly are LayerZero and Pellegrino accused of?
The claim was filed with the Supreme Court of British Columbia on Wednesday, September 23. It makes three claims: negligent misrepresentation, negligence and defamation. The defamation claim concerns statements LayerZero made after the hack. The company publicly said the single-verifier setup contradicted a multi-DVN model it had supposedly recommended to every integration partner. Days later, LayerZero admitted it had made a mistake by allowing its own DVN to act as a sole verifier for high-value transactions. Evercrest argues the two statements contradict each other and damaged its reputation. The claimed damages are sizable, covering direct losses as well as aggravated and punitive damages.
"The claim continues to be meritless. I will meet them in Vancouver and defend myself accordingly."
- Bryan Pellegrino, co-founder of LayerZero, from a post on X, September 25, 2026
How did the hack ripple through the DeFi market?
The fallout reached well beyond KelpDAO. Aave, the largest lending protocol, had to borrow $300 million to meet a surge in withdrawal requests from users spooked by the hack. Within days of the attack, DeFi lost $20 billion in total value locked. CoinDesk described the liquidity crunch as one of the largest waves of DeFi withdrawals in the market's history. Analysts at JPMorgan said afterward that the incident exposed structural risks that still remain in decentralized finance. The KERNEL token, tied to KelpDAO's ecosystem, dropped so sharply that some crypto exchanges warned users about the added risk. The lawsuit lists the damages. It cites 2,000 ETH contributed to restore rsETH's backing, and more than $650 million withdrawn from the protocol since the exploit.
What happens next?
Pellegrino has already called the claims meritless and said he will defend himself in person. None of the lawsuit's allegations has been tested in court, and LayerZero has not yet filed a formal response. KelpDAO has already moved the rsETH bridge to a more secure cross-chain verification standard, though that does not undo the lawsuit itself. The case is shaping up as one of the first major tests of who actually bears responsibility for a failure in cross-chain infrastructure: the protocol itself or the bridge provider. For an industry where bridges move billions of dollars between chains every day, the answer could shape how such partnerships get structured going forward.




Comments
Your email address will not be published. Required fields are marked *