Kelp's Operator Sues LayerZero in Vancouver Over $292M rsETH Loss

The company behind the Kelp restaking protocol has taken its April losses to court. Evercrest Technologies filed a notice of civil claim in the Supreme Court of British Columbia this week against LayerZero Labs, its Canadian arm and co-founder Bryan Pellegrino. The claim is that LayerZero reviewed and endorsed in writing the single-verifier bridge setup an attacker broke on 18 April, carrying off 116,500 rsETH worth about $292 million, and said nothing about the weaknesses in it. Pellegrino calls the claim meritless. More than $650 million has left Kelp since the exploit, by The Block's count.
One attester, no second opinion
LayerZero carries messages between blockchains. Whether a message is genuine is attested by a decentralized verifier network, or DVN, and Kelp ran a 1-of-1 configuration: one attester, nothing checking it. That setup is the centre of the case. LayerZero's own incident report put the loss on compromised internal nodes and a single verification path, and said it had recommended using more than one verifier network. Kelp's answer is that its configuration had been confirmed as secure with LayerZero before it went live.
The attack began well before the money moved. A developer was socially engineered on 6 March, handing the attacker credentials to LayerZero's RPC cloud environment, the service that feeds chain data to its nodes. Internal nodes were altered. During a denial-of-service attack on outside data providers, those nodes served false chain data, a verifier signed a forged cross-chain message on the strength of it, and the bridge released the rsETH. That sequence comes from crypto.news and The Crypto Times. The other three accounts carry no equivalent.
Two exchanges in 2024 carry the claim
The Block, which has read the filing most closely of the available accounts, lists the causes of action as negligent misrepresentation, negligence and defamation, with compensatory, aggravated and punitive damages sought. Evercrest points to two exchanges with LayerZero, on its reading: an assurance on 2 February 2024 that there was "no problem" with the default configuration, and a direction on 21 March 2024 to use the same setup as another bridge. The defamation count has no counterpart in the technical dispute. It goes to what LayerZero said in public once the money was gone.
"The claim continues to be meritless. I will meet them in Vancouver and defend myself accordingly," Pellegrino said, in wording five outlets carried identically.
The accounts disagree on both dates
The Block, Cointelegraph, The Crypto Times and crypto.news date the exploit 18 April. CoinDesk's Friday piece says 22 April. This desk's 6 September tally of the year's DeFi losses used 18 April and about $290 million, alongside Drift Protocol's roughly $285 million on 1 April. The filing date splits the same way. The Block says 25 September; The Crypto Times and crypto.news say 24 September, and The Crypto Times alone gives a court file number, 267169. Neither gap is explained anywhere in the five accounts.
Even the plaintiff is rendered two ways. CoinDesk and Cointelegraph name KelpDAO as the party suing, the other three name Evercrest Technologies. Same claim, two levels of formality, and no account says so.
The token has already moved on
Kelp shifted rsETH off LayerZero's token framework to Chainlink's cross-chain protocol, which Cointelegraph describes as planned and crypto.news as finished by May. We could not establish which account is current. The receipt token has had a hard year on its own account: a Safe wallet lost about $7.8 million of rsETH to a module exploit on 16 September, in an incident unrelated to any bridge.
Some of April's money is accounted for. The Crypto Times reports that Arbitrum's Security Council froze roughly 30,766 ETH, about $71 million, of the stolen collateral. CoinDesk alone writes that the exploit erased $20 billion of value locked across DeFi and pushed Aave to borrow $300 million to cover withdrawals. Both figures stand unverified. crypto.news says a defendant served in Canada generally has 21 days to respond, which nobody else mentions. No court has yet tested whether signing off on a customer's security configuration makes a protocol liable for what that configuration lets through.
Read also: ZetaChain Votes 99.4% to Retire Its Layer 1 and Move ZETA to Solana