NewsCryptoKelpDAO Files Civil Claim in British Columbia Against LayerZero Over $292M rsETH Exploit

KelpDAO Files Civil Claim in British Columbia Against LayerZero Over $292M rsETH Exploit

Author: Crypto Adventure·

Key Takeaways

  • •Evercrest Technologies, the legal entity behind KelpDAO, has sued LayerZero and co-founder Bryan Pellegrino in British Columbia over the April 18 rsETH bridge exploit that caused losses of about $292 million.
  • •Kelp's claim alleges LayerZero failed to disclose technology risks, permitted the compromise of cross-chain verification infrastructure, and endorsed Kelp's bridge deployment in writing, though the allegations have not been tested in court.
  • •LayerZero's final report traced the breach to a March 6 social-engineering attack on a developer, and compromised internal RPC nodes later enabled a forged message that released 116,500 rsETH without a-chain burn.
  • •LayerZero maintains that Kelp's 1-of-1 DVN configuration was the decisive single point of failure and that it had advised using multiple independent verifiers, while Pellegrino has called the claim meritless.
  • •Security firms Mandiant and CrowdStrike attributed the intrusion to the North Korea-linked TraderTraitor group, and Kelp has since moved rsETH to Chainlink's Cross-Chain Interoperability Protocol.
KelpDAO Files Civil Claim in British Columbia Against LayerZero Over $292M rsETH Exploit

Evercrest Technologies, the legal entity behind KelpDAO, has filed a civil claim in British Columbia against LayerZero and co-founder Bryan Pellegrino over the April 18 rsETH bridge exploit that resulted in losses of approximately $292 million. The filing was announced in a post on X.

Kelp says the defendants failed to adequately disclose risks in LayerZero's technology and failed to prevent attackers from compromising the infrastructure used to verify cross-chain transactions. The claim further alleges that LayerZero reviewed and approved Kelp's bridge deployment and configuration in writing before the attack. Those allegations have not been adjudicated.

The legal action follows months of disagreement over an exploit in which 116,500 rsETH was released from an Ethereum bridge contract without a corresponding burn on the source chain. In bridge mechanics, that burn is what offsets released tokens one-for-one by destroying their counterparts on the originating chain; without it, the rsETH released on Ethereum had no offsetting destruction behind it.

LayerZero Infrastructure Was Compromised Before rsETH Release

LayerZero's final incident report traced the intrusion to March 6, when an attacker socially engineered a LayerZero developer and obtained session credentials. The attacker subsequently entered LayerZero's cloud environment and modified internal RPC nodes used by the LayerZero Labs Decentralized Verifier Network (DVN), the layer responsible for attesting that cross-chain messages are legitimate before bridges act on them.

On April 18, external RPC providers, the services that relay blockchain data to applications and verifiers, were hit with a denial-of-service attack, leaving the verifier dependent on compromised internal nodes that supplied false blockchain state. The LayerZero Labs DVN then generated a valid attestation for a forged cross-chain message, and Kelp's Ethereum bridge released 116,500 rsETH even though the corresponding source-chain burn had never occurred.

A second forged message targeting another 40,000 rsETH was authenticated but did not execute after Kelp paused the affected contracts. Security firm Blockaid independently identified the 1-of-1 verification path and confirmed, in its analysis, that no second verifier was present to reject the false message.

Lawsuit Targets Dispute Over 1-of-1 DVN Setup

LayerZero has maintained that Kelp's bridge configuration created the decisive single point of failure. In its April incident statement, the company said rsETH relied on a 1-of-1 DVN configuration, meaning the LayerZero Labs verifier alone could authorize a cross-chain message. LayerZero said it had recommended the use of multiple independent verifiers and argued that a multi-DVN setup would have prevented a single compromised verification path from releasing funds.

Kelp disputes that account. Its civil claim says LayerZero reviewed and endorsed the deployment and configuration before the exploit, placing the question of what LayerZero approved and what security warnings it provided at the center of the case. Pellegrino has called the claim meritless and said he intends to defend the case in Vancouver.

DPRK-Linked TraderTraitor Attributed to Attack

LayerZero's final investigation said Mandiant, CrowdStrike and independent security researchers attributed the intrusion to TraderTraitor, also tracked as UNC4899, a North Korea-linked threat actor.

Chainalysis separately described the incident as an attack on off-chain verification infrastructure rather than a vulnerability in the rsETH token contract itself. Its investigation found that the LayerZero-operated RPC infrastructure feeding the verifier had been manipulated before the forged message was accepted. That distinction now underpins the legal dispute, since Kelp's claim alleges the defendants failed to prevent the compromise of exactly that off-chain verification infrastructure.

Kelp subsequently moved rsETH to Chainlink's Cross-Chain Interoperability Protocol (CCIP) as part of a wider reassessment of its cross-chain security architecture.

The British Columbia civil case now puts the parties' competing accounts of the bridge configuration, LayerZero's security disclosures, and responsibility for the compromised verification infrastructure before the court.