Evercrest Technologies, the parent company of liquid restaking protocol KelpDAO, filed a civil lawsuit on September 24, 2026, in the Supreme Court of British Columbia against LayerZero Labs and its CEO Bryan Pellegrino. The suit alleges negligent misrepresentation, negligence, and defamation rela...
"The claim continues to be meritless, will meet them in Vancouver and defend myself accordingly." — Bryan Pellegrino, CEO, LayerZero Labs
Evercrest Technologies, the parent company of liquid restaking protocol KelpDAO, filed a civil lawsuit on September 24, 2026, in the Supreme Court of British Columbia against LayerZero Labs and its CEO Bryan Pellegrino. The suit alleges negligent misrepresentation, negligence, and defamation related to the April 18 bridge exploit that drained 116,500 rsETH — approximately $292 million at the time — in what remains the largest single DeFi exploit of 2026.
The case centers on a disputed question: who chose and who approved the single-verifier bridge configuration that enabled the attack. Evercrest alleges LayerZero reviewed and endorsed the 1-of-1 DVN setup in writing on at least three occasions between February 2024 and January 2025. LayerZero maintains KelpDAO independently downgraded from a 2-of-2 default to a 1-of-1 configuration against its recommendations. At the time of the exploit, 47% of approximately 2,665 active LayerZero-based applications were running the same single-verifier setup.
The lawsuit marks a watershed moment for DeFi infrastructure liability. For the first time, a protocol developer is suing a cross-chain messaging provider in a traditional court, asserting that middleware vendors bear a duty of care for the security configurations they advise. The outcome could establish legal precedent for how responsibility is allocated across the multi-layer stack of decentralized applications.
At 17:35 UTC on Saturday, April 18, 2026, an attacker minted 116,500 rsETH on Ethereum mainnet with no backing assets behind them — roughly 18% of KelpDAO's entire circulating supply, valued at approximately $292 million. The transaction hash (0x1ae232...b4222) shows the payload targeted LayerZero's EndpointV2 contract before being transmitted to KelpDAO's rsETH OFT adapter.
LayerZero attributed the attack with "preliminary confidence" to North Korea's Lazarus Group, specifically the TraderTraitor subunit, in a post-mortem published April 20, according to Unchained Crypto. The attack vector did not exploit a smart contract vulnerability. Instead, the attacker:
KelpDAO's bridge configuration at the time: Required DVNs: 1 (LayerZero Labs only). Optional DVNs: 0. A single forged signature was sufficient to authorize the token release.
KelpDAO paused rsETH contracts across Ethereum and all Layer 2 networks within 46 minutes. On-chain analysts publicly identified the OApp configuration within approximately three hours.
The stolen rsETH did not simply disappear. Within minutes, the attacker deposited the unbacked tokens as collateral on Aave V3 and V4, borrowing real assets against worthless collateral:
| Platform | Asset Borrowed | Approximate Value | |----------|---------------|-------------------| | Aave V3/V4 Ethereum | 52,834 WETH | ~$113M | | Aave V3/V4 Arbitrum | 29,782 WETH + 821 wstETH | ~$64M+ | | Compound V3/Euler | Undisclosed | Additional positions |
Total extracted value ranged between $200 million and $236 million, according to DeFi Prime. Aave was left carrying between $177 million and $196 million in bad debt. Within 24 hours, Aave's TVL dropped by approximately $6 billion, its WETH market hit 100% utilization, and the AAVE token fell more than 18%.
The contagion spread further. KelpDAO's rsETH integrations were paused across Ethena, Yearn, Pendle, Beefy, Compound V3, and Euler. Bridged rsETH on 20-plus Layer 2 networks and sidechains became structurally impaired. KelpDAO recorded over $650 million in user withdrawals in the months following the exploit, according to court filings. The protocol's planned sbUSD stablecoin launch was cancelled.
The Arbitrum Security Council froze and helped recover roughly $70 million worth of ether linked to the attacker. Five days after the exploit, Aave launched "DeFi United," a coordinated industry recapitalization initiative, with Lido Finance, EtherFi, and Aave founder Stani Kulechov proposing to contribute ether to cover the shortfall, according to CoinDesk.
The lawsuit's core factual question: who chose the 1-of-1 DVN setup?
Evercrest's position, per the filed claim:
LayerZero's position, per its April 19 public statement and May incident report:
The Defiant reported that LayerZero's own incident report confirmed KelpDAO had originally deployed with a 2-of-2 configuration before switching to 1-of-1. The timeline and circumstances of that switch remain disputed.
Evercrest's notice of civil claim, filed September 24 in Vancouver, names three causes of action:
1. Negligent Misrepresentation. Evercrest alleges LayerZero made false statements about the safety of the 1-of-1 configuration that Evercrest relied upon when deploying the bridge.
2. Negligence. The claim alleges LayerZero owed a duty of care as an infrastructure provider and failed to warn KelpDAO of known risks, failed to implement safeguards against single-point-of-failure exploitation, and failed to extend security warnings it gave other integrators.
3. Defamation (with punitive and aggravated damages). Evercrest alleges LayerZero's public statements after the exploit — blaming KelpDAO's configuration choices — were false and damaged Evercrest's reputation, contributing to the withdrawal cascade and KERNEL token decline.
Evercrest claims damages in the "tens of millions of dollars," including 2,000 ETH invested to restore rsETH backing, exchange and regulatory alerts triggered by token declines, and the cancellation of planned product launches. Specific total damages were not enumerated in the filing.
Pellegrino responded on social media: "The claim continues to be meritless." He stated he would defend himself and LayerZero in British Columbia court.
After the exploit, LayerZero enacted several policy changes:
That acknowledgment may complicate LayerZero's legal defense. Admitting the configuration was a "mistake" while arguing the lawsuit is "meritless" creates a tension that Evercrest's attorneys will likely seek to exploit.
KelpDAO, for its part, completed migration of rsETH from LayerZero to Chainlink's Cross-Chain Interoperability Protocol (CCIP) in May 2026.
The KelpDAO exploit exposed a structural issue far beyond a single bridge. At the time of the attack, 47% of approximately 2,665 applications built on LayerZero were operating with the same single-verifier configuration, according to on-chain analysis cited by Cryptopolitan. That represents roughly 1,250 applications running a setup that a state-sponsored attacker had already demonstrated could be compromised.
The broader context: cross-chain bridges have lost more than $1 billion in 2026 through approximately 140 exploits, according to DefiLlama data through mid-September. Bridges account for approximately 42% of all crypto exploit losses despite securing a fraction of total DeFi value. With bridges collectively securing approximately $45 billion in TVL as of late June, the annualized loss rate approaches 3-4% of secured value — a figure that would be unacceptable in regulated financial infrastructure.
Bridge exploits represented over 68% of all DeFi losses in Q1 2026 alone, according to KuCoin research. The Kansas City Federal Reserve flagged in an April 2026 report that "interoperability rails" have created systemic risk where a single bridge exploit can destabilize the $300 billion stablecoin market.
The Evercrest v. LayerZero case raises questions that extend beyond the two parties:
Duty of care. If a court finds that messaging protocol providers owe a duty of care to integrating applications, it could impose liability on infrastructure vendors for how their products are configured by third parties. This would represent a significant shift from the prevailing assumption that open-source protocol developers bear limited responsibility for downstream deployments.
Configuration as advice. The allegation that LayerZero "endorsed" a specific configuration in writing — if supported by evidence — could establish that reviewing and approving an integrator's setup constitutes professional advice carrying legal weight.
Post-incident statements. The defamation claim introduces a secondary risk for infrastructure providers: that public post-mortems assigning blame could themselves generate legal liability if the claims prove inaccurate.
Jurisdictional choice. Filing in British Columbia rather than in the United States or a crypto-friendly offshore jurisdiction signals Evercrest's intent to pursue the case in a common-law system with established negligence and misrepresentation frameworks.
No comparable case — a DeFi protocol suing its infrastructure provider in a traditional court for bridge security failures — has proceeded to trial. The closest precedents involve centralized exchange hack liability, which operate under fundamentally different legal theories.
The Evercrest v. LayerZero case is not merely a dispute over $292 million. It is a test of whether the multi-layer DeFi stack — where protocols depend on messaging layers, which depend on verifier networks, which depend on RPC infrastructure — carries any enforceable allocation of responsibility.
DeFi's composability has always been described as a feature. This lawsuit treats it as a liability chain. If British Columbia's court agrees that infrastructure providers bear responsibility for the configurations they review and endorse, the cost of building middleware will rise. If the court sides with LayerZero's position that application-level choices are outside the infrastructure vendor's scope, the question of who bears the cost when bridges fail — already at $1 billion in 2026 alone — remains unanswered.
For DeFi protocols evaluating bridge and middleware dependencies, the economic calculation has changed. The value at risk is not only the funds in the bridge. It is the cascading losses across every protocol that touches the bridged asset, the reputational damage from public blame disputes, and now, the cost of litigation in traditional courts.