NewsCryptoKelpDAO developer sues LayerZero and CEO Bryan Pellegrino in Canada over $292 million rsETH exploit

KelpDAO developer sues LayerZero and CEO Bryan Pellegrino in Canada over $292 million rsETH exploit

Author: Cryptopolitan·

Key Takeaways

  • •Evercrest Technologies, the developer behind KelpDAO, filed a claim for negligence, defamation and negligent misrepresentation against LayerZero, its Canadian arm and CEO Bryan Pellegrino in a British Columbia court on Thursday.
  • •The lawsuit centers on the April 18 theft of 116,500 rsETH, valued at roughly $292 million at the time, which Evercrest says began with a single LayerZero developer's computer compromised through social engineering and malware.
  • •Evercrest alleges LayerZero warned the USDT0 developer about the risks of default verifier setups in late 2024 or early 2025 while never issuing a similar warning to Kelp, forming the core of the negligent misrepresentation count.
  • •KelpDAO withdrawals have topped $650 million since April, and the project shut down its planned sbUSD stablecoin and chose Chainlink's CCIP in May as its new cross-chain security standard.
  • •Pellegrino responded on X that the claim continues to be meritless and that he will defend himself, while none of the allegations have yet been tested in court.
KelpDAO developer sues LayerZero and CEO Bryan Pellegrino in Canada over $292 million rsETH exploit

LayerZero, its Canadian arm and CEO Bryan Pellegrino were named as defendants Thursday in a negligence and defamation claim filed before British Columbia's top trial court. Evercrest Technologies, the developer behind KelpDAO, ties the case to the April 18 heist of 116,500 rsETH, Kelp's liquid restaking token, which was worth about $292 million at the time.

The claim, filed in the Vancouver registry, adds negligent misrepresentation to the counts and seeks aggravated and punitive damages in addition to ordinary damages. The full filing is available here. None of the allegations have been tested in court.

Evercrest alleges it was never warned about verifier risks

LayerZero's own verifier was the only one needed to sign off before rsETH locked on one chain could be minted on another. Kelp's bridge utilized a 1-of-1 decentralized verifier network, or DVN. The exploit was "a failure of LayerZero's own security infrastructure," Evercrest's filing says.

Evercrest alleges LayerZero told it on Feb. 2, 2024, that the default setting presented "no problem." The claim says that on March 21, 2024, LayerZero told Evercrest to clone the 1-of-1 setup of another bridge. LayerZero's pitch, dated Jan. 2025 in the filing, was a redundant and monitored verifier network, where a compromised verifier could at most "fail to verify a message correctly."

USDT0 received a different message, the claim alleges. Evercrest says Kelp never received a warning, while LayerZero warned the USDT0 developer about the risks of default verifier setups in late 2024 or early 2025, and that developer went on to run its own verifier. That alleged difference in warnings is central to the negligent misrepresentation count.

Withdrawals topped $650 million after the April 18 exploit

The claim puts the breach inside of LayerZero. According to Evercrest, the attacker's entry point was a single LayerZero developer's computer compromised via social engineering and malware, and the rsETH transaction was sent on April 18 at around 17:35 UTC.

The filing says Kelp shut down its planned sbUSD stablecoin after the attack and is moving rsETH to another cross-chain security standard. Kelp selected Chainlink's CCIP in May, as Cryptopolitan reported. According to Evercrest, KelpDAO withdrawals have topped $650 million since April.

The defamation count relates to LayerZero's reaction to the hack. Its post-mortem said Kelp's setup "directly contradicts" the multi-DVN model LayerZero advocates. Evercrest folds that line, along with Pellegrino's public blame, into its case.

Pellegrino said in May that Kelp's account was "completely untrue" and that Kelp was launched on LayerZero's multi-DVN default and converted to 1-of-1 itself, Cryptopolitan reported. Responding to the new filing on X, he said the claim "continues to be meritless" and that he would defend himself.

Cryptopolitan reported that 47% of active LayerZero app contracts were running 1-of-1 setups at the time of the exploit — a configuration LayerZero has since banned. The suit will next move through the B.C. court process, where LayerZero and Pellegrino have the opportunity to file a formal response.

Source: Cryptopolitan