NewsCryptoKelpDAO Developer Sues LayerZero and CEO Bryan Pellegrino Over $292M Bridge Exploit

KelpDAO Developer Sues LayerZero and CEO Bryan Pellegrino Over $292M Bridge Exploit

Author: Decrypt·

Key Takeaways

  • •Evercrest Technologies filed a notice of civil claim in the Supreme Court of British Columbia naming LayerZero Labs Ltd., LayerZero Labs Canada Inc., and CEO Bryan Pellegrino personally, pleading negligent misrepresentation, negligence, and defamation while seeking aggravated and punitive damages.
  • •The claim alleges LayerZero called KelpDAO's draft code good in February 2024 and explicitly directed a 1-of-1 verifier setup in March 2024, then later publicly stated it had consistently recommended a multi-verifier model instead.
  • •According to the filing, the attack began with malware placed on a LayerZero developer's computer, allowing the attacker to manipulate verifier data and mint 116,500 rsETH without backing on April 18, though Evercrest paused the bridges within about an hour.
  • •Evercrest asserts that LayerZero warned another developer, USDT0, about risks in default verifier configurations but gave KelpDAO no comparable warning, and that LayerZero later admitted a mistake in allowing its verifier to act as the sole check for high-value transactions.
  • •Claimed damages include a 2,000 ETH contribution to restore rsETH backing, more than $650 million withdrawn since the exploit, and a fall in the KERNEL token price that prompted warnings from regulators and exchanges.
KelpDAO Developer Sues LayerZero and CEO Bryan Pellegrino Over $292M Bridge Exploit

Evercrest Technologies, the company behind the restaking protocol KelpDAO, has filed a civil claim against LayerZero, its Canadian subsidiary and LayerZero co-founder and chief executive Bryan Pellegrino over the April exploit that drained $292 million from the protocol, alleging LayerZero endorsed in writing the exact bridge configuration it later blamed for the loss.

The notice of civil claim — the document that initiates a civil action in the province — was filed Wednesday in the Supreme Court of British Columbia and names LayerZero Labs Ltd., LayerZero Labs Canada Inc. and Pellegrino, who is sued personally over posts on Telegram and X. It pleads negligent misrepresentation, negligence and defamation, and seeks aggravated and punitive damages. The company announced the suit on X:

— Kelp (@KelpDAO) September 25, 2026

The dispute touches a broader question in cross-chain infrastructure: where responsibility sits when a bridge's verifier configuration is set by the messaging layer it is built on, and that configuration proves to be the weak point an attacker uses.

At the center of the dispute is the security setup of KelpDAO's cross-chain bridges. The bridges ran a 1-of-1 configuration, meaning LayerZero's own verifier network was the only party confirming that tokens had been locked on one chain before equivalent tokens were minted on another. Evercrest says that setup was LayerZero's instruction. According to the filing, LayerZero told the company in February 2024 that its draft code was "good" and that there was "[n]o problem" using the default configuration, then in March 2024 explicitly directed it to use a 1-of-1 setup with LayerZero's own verifier. In January 2025, per the filing, LayerZero said that even if a verifier were compromised, the most it could do was fail to verify a message correctly.

The filing also states that LayerZero warned a separate developer, USDT0, about risks in its default verifier configurations in late 2024 or early 2025, prompting that developer to run its own verifier. Evercrest says it received no comparable warning.

The attack described in the claim began inside LayerZero itself, six weeks before any funds moved. An attacker placed malware on a LayerZero developer's computer on March 6, then tampered with LayerZero's nodes so they fed false readings to its verifier. On April 18, the attacker disabled the third-party nodes the verifier also relied on, causing it to be told that 116,500 rsETH had been locked on Unichain when nothing had been. With only one verifier required, the tokens were minted unbacked. Evercrest says it paused the bridges within about an hour and blocked a second attempt.

The defamation claims turn on what followed. LayerZero's incident statement said the single-verifier setup contradicted a multi-DVN model, shorthand for a decentralized verifier network, it had "consistently recommended to all integration partners," and Pellegrino wrote that "[n]obody should be relying on sole DVN." Days later, according to the filing, LayerZero admitted it had "made a mistake by allowing [its] DVN to act as a 1-of-1 DVN for high-value transactions."

Evercrest claims damages including a 2,000 ETH contribution made to restore rsETH's backing, more than $650 million withdrawn since the exploit, and a fall in the price of the KERNEL token that drew warnings from regulators and exchanges.

In a post on X, Pellegrino said the claim "continues to be meritless" and that he would meet Evercrest in Vancouver to defend himself.

None of the allegations has been tested in court, and no response to the claim has been filed. A response, when it comes, will give the court the defendants' account of the same events.