On September 24, 2026, Evercrest Technologies Inc., the corporate entity behind liquid restaking protocol KelpDAO, filed a notice of civil claim (Case No. 267169) in the Supreme Court of British Columbia against LayerZero Labs Ltd. and co-founder Bryan Pellegrino. The suit stems from an April 18 ...
"These allegations are meritless. I will meet them in Vancouver." — Bryan Pellegrino, Co-founder and CEO, LayerZero Labs, September 24, 2026
On September 24, 2026, Evercrest Technologies Inc., the corporate entity behind liquid restaking protocol KelpDAO, filed a notice of civil claim (Case No. 267169) in the Supreme Court of British Columbia against LayerZero Labs Ltd. and co-founder Bryan Pellegrino. The suit stems from an April 18 exploit that drained 116,500 rsETH—approximately $292 million—from KelpDAO's cross-chain bridge built on LayerZero V2 infrastructure. It is the largest civil action to arise from a single DeFi exploit in 2026.
The filing pleads negligent misrepresentation, negligence, and defamation, and seeks aggravated and punitive damages. Evercrest alleges that LayerZero reviewed and endorsed, in writing, the bridge's single-validator configuration before the attack, then publicly blamed KelpDAO for its own infrastructure failures after the breach. LayerZero denies the claims. The case may establish precedent for how courts allocate liability between cross-chain messaging protocols and the applications that deploy on them.
Chainalysis attributed the attack to North Korea's Lazarus Group, specifically the TraderTraitor cluster. The downstream damage extended well beyond KelpDAO: Aave V3 absorbed between $123 million and $230 million in bad debt, Arbitrum's Security Council froze $71 million in exploiter funds, and rsETH markets were paused across multiple lending protocols for weeks.
The attack began weeks before the actual theft. On March 6, 2026, according to the civil claim, an attacker used social engineering to compromise a LayerZero developer's workstation, harvesting session keys and gaining access to the company's RPC cloud environment.
On April 18 at 17:35 UTC, the attacker executed the drain. The sequence, reconstructed from on-chain data by Blockaid and Hypernative:
Forged packet creation. The attacker crafted a LayerZero cross-chain message that claimed to originate from KelpDAO's Unichain deployment. Independent verification found zero PacketSent events from Unichain's LayerZero endpoint during the relevant block window and no rsETH burn events on Unichain. The total rsETH supply on Unichain at the time was approximately 49 tokens; the forged packet claimed to bridge 116,500—roughly 2,300 times the actual supply.
DVN attestation. The compromised Decentralized Verifier Network (DVN) signed a payload hash for the fabricated event. Two of three multisig signers produced valid ECDSA signatures, satisfying the 2-of-3 quorum within the DVN itself. Because KelpDAO's configuration required only one DVN, no independent verifier existed to catch the false attestation.
Escrow drain. LayerZero's ReceiveUln302.verify() function stored the payload hash and recorded the packet as verified. The Executor then invoked lzReceive() on KelpDAO's OFTAdapter, which released 116,500 rsETH to attacker address 0x1F4C...adeF. The OFTAdapter held approximately $1.07 billion in total value locked across 20+ networks at the time.
Liquidation. Between 17:35 and 17:46 UTC—11 minutes—the attacker deposited approximately 89,567 rsETH into Aave V3 on Ethereum and Arbitrum, borrowing roughly 82,650 WETH and 821 wstETH against it. The attacker then consolidated 52,440 ETH into a single address.
Second attack blocked. At approximately 18:21 UTC, 46 minutes after the initial drain, KelpDAO's emergency multisig froze core contracts. This blocked a second forged packet targeting an additional 40,000 rsETH (~$100 million).
No smart contract vulnerability was exploited. According to Blockaid's analysis, "the OFTAdapter did exactly what it was built to do." The failure was entirely in the off-chain signing infrastructure and the bridge's verification configuration.
LayerZero V2 replaced traditional multisig bridge models with Decentralized Verifier Networks. DVNs are off-chain entities that monitor source-chain events and cryptographically attest to their occurrence before destination contracts release funds. The protocol's architecture delegates the choice of DVN configuration to the deploying application.
KelpDAO's bridge was configured with requiredDVNCount set to 1, using only LayerZero Labs' own DVN, with zero optional DVNs. This is referred to as a "1-of-1" configuration. In this setup, a single compromised verifier—whether through key theft, RPC node poisoning, or internal pipeline manipulation—is sufficient to forge any arbitrary cross-chain message.
Industry best practice, according to LayerZero's own post-incident statement, calls for "2-of-N" configurations requiring multiple independent verifiers.
Blockaid's post-mortem identified two possible compromise vectors: direct compromise of the DVN's private signing keys (through social engineering or infrastructure breach), or compromise of the DVN operator's off-chain node or message-delivery pipeline. The civil claim points to the social engineering incident on March 6 as the entry point.
A critical detail in the dispute: KelpDAO's OFTAdapter had no per-packet caps, no supply reconciliation checks, and no anomaly detection. Hypernative's analysis noted the forged packet exceeded the largest prior inbound transfer by 327 times, yet no circuit breaker triggered.
The central factual question in this case is who chose the 1-of-1 configuration and who understood its risks.
LayerZero's position: Pellegrino stated on May 5, 2026 that KelpDAO "manually switched to 1-of-1 DVN configurations on April 1, 2024," contrary to documented defaults. LayerZero's post-incident statement characterized the configuration as the application's responsibility under LayerZero V2's permissionless design.
KelpDAO's position: According to a source cited by CoinDesk on April 20, LayerZero's own quickstart guide and default GitHub configuration pointed to a 1-of-1 DVN setup. The source added that 40% of protocols on LayerZero were using the same configuration at the time of the exploit. Evercrest's civil claim alleges that LayerZero "reviewed and endorsed, in writing" the deployment configuration.
The question of what constitutes a "default" versus a "custom choice" in a permissionless protocol is likely to be central to the trial. If 40% of all LayerZero-deployed bridges were running the same configuration, the argument that it represented a reckless deviation from best practice becomes harder to sustain.
The notice of civil claim, filed September 24, 2026, in the Supreme Court of British Columbia (Case No. 267169), names two defendants: LayerZero Labs Ltd. (through its Canadian arm) and Bryan Pellegrino personally.
The three causes of action:
Negligent misrepresentation. Evercrest alleges LayerZero provided assurances about the security and suitability of the bridge configuration that were inaccurate or incomplete.
Negligence. The claim alleges LayerZero failed to prevent infiltration of its own infrastructure—specifically the developer workstation compromise that gave the attacker access to RPC systems—and failed to adequately disclose technology weaknesses.
Defamation. Evercrest alleges LayerZero and Pellegrino "publicly blamed us for their failures," causing reputational harm.
The filing seeks aggravated and punitive damages. No specific dollar amount has been disclosed in public filings, though the underlying loss was $292 million.
Pellegrino responded on September 24 at 22:57 UTC, describing the claims as "meritless" and stating he would appear in Vancouver to defend the case. KelpDAO issued a statement at 03:56 UTC on September 25, framing the filing as an effort to "right the wrongs associated with the exploit of rsETH's LayerZero bridge."
The exploit's impact radiated through DeFi's interconnected lending and governance systems.
Aave V3. The attacker deposited stolen rsETH as collateral to borrow WETH, creating what Aave's governance forum described as "unliquidatable bad debt"—the collateral's economic backing was hollow because no real rsETH had been burned on the source chain. Aave Guardian froze rsETH markets across all V3 deployments at 18:52 UTC on April 18. Bad debt estimates ranged from $123 million to $230 million, exceeding what the protocol's insurance mechanisms could cover.
Arbitrum Security Council. The council traced and froze 30,765.67 ETH ($71 million) on April 21. A subsequent governance proposal—supported by more than 90% of voters—approved releasing the funds to a 2-of-3 Gnosis Safe co-signed by Aave, Kelp DAO, and Certora, designated for rsETH recovery. The release proceeded in May despite a parallel U.S. law enforcement seizure effort.
SparkLend and Fluid. Both protocols froze rsETH markets independently. According to one analysis, the exploit temporarily erased approximately $14 billion in DeFi TVL within 48 hours as users pulled collateral from protocols accepting restaking tokens.
Recovery. Aave governance reported that rsETH backing was fully restored by June 1, 2026, aided by the Arbitrum fund release and contributions from LayerZero, EtherFi, and Compound.
LayerZero implemented immediate policy changes after the exploit:
DVN refusal policy. LayerZero's DVN will no longer sign or attest messages from any application using a 1-of-1 configuration. This effectively converts a recommendation into an enforced requirement.
Migration outreach. The company began contacting projects still running 1-of-1 setups to assist migration to multi-DVN models with redundancy.
Configuration transparency. Several bridge monitoring services, including Hypernative, now flag single-DVN deployments as a risk indicator in real time.
The broader DeFi lending sector also reacted. Aave's governance passed a post-rsETH collateral framework implementing tier-based loan-to-value reductions and wrap-depth ineligibility limits for bridged assets. The framework effectively requires any cross-chain collateral token to demonstrate multi-verifier bridge security before acceptance.
This case sits at the intersection of several unresolved legal questions in DeFi:
Protocol liability. LayerZero V2's design philosophy delegates configuration choices to deployers. If a court finds that LayerZero's endorsement of the configuration created a duty of care, it could reshape the liability model for all permissionless infrastructure protocols.
Default settings as implied recommendations. If the court accepts that LayerZero's default GitHub configuration constituted an implied recommendation of the 1-of-1 setup, protocol developers may face new obligations around the security implications of their default parameters.
State actor attribution. The Lazarus Group attribution introduces questions about foreseeability. Were the security risks of a 1-of-1 DVN configuration reasonable against a backdrop of state-sponsored attackers with demonstrated capabilities against crypto infrastructure?
Jurisdictional precedent. The filing in British Columbia, rather than a U.S. court, may reflect strategic considerations around Canadian tort law. The outcome could influence where future DeFi disputes are litigated.
No trial date has been set.
The Evercrest v. LayerZero case puts on trial a structural question that the cross-chain bridge sector has avoided answering through code alone: when a permissionless protocol offers a configuration option that proves catastrophically insecure, who bears the loss?
The factual record contains ammunition for both sides. LayerZero can point to the application's configuration choice and the protocol's permissionless design philosophy. KelpDAO can point to the default settings, the written endorsement it claims to hold, and the 40% of protocols running the same setup. A British Columbia court will now attempt to draw a line that smart contracts could not.
Whatever the outcome, the exploit has already forced a practical resolution. LayerZero's DVN no longer signs for 1-of-1 configurations. Aave has tightened collateral requirements for bridged assets. The $292 million loss has been substantially recovered. But the legal question—whether infrastructure protocols owe a duty of care to applications built on their defaults—remains open. The answer will shape how cross-chain systems are built, configured, and governed for years to come.