Summary

  • Evercrest Technologies has lodged a civil lawsuit against LayerZero, its Canadian subsidiary, and co-founder Bryan Pellegrino in the Supreme Court of British Columbia.
  • The lawsuit accuses the defendants of negligent misrepresentation, negligence, and defamation related to the $292 million exploit that occurred in April.
  • It claims that the attack was initiated by malware on a LayerZero developer's device six weeks before any funds were affected.

The developer responsible for KelpDAO has taken legal action against LayerZero and its CEO following an exploit that resulted in the loss of $292 million from the restaking protocol in April. The lawsuit asserts that LayerZero had previously endorsed the bridge configuration that it later criticized as the cause of the exploit.

On Wednesday, Evercrest Technologies filed a civil claim in the Supreme Court of British Columbia, naming LayerZero Labs Ltd., LayerZero Labs Canada Inc., and Bryan Pellegrino personally due to statements made on Telegram and X. The suit includes allegations of negligent misrepresentation, negligence, and defamation, seeking both aggravated and punitive damages.

https://t.co/D17UbUbixh

— Kelp (@KelpDAO) September 25, 2026

KelpDAO's bridge utilized a 1-of-1 configuration, meaning that only LayerZero's verifier network confirmed that tokens were locked on one chain before issuing equivalent tokens on another.

Evercrest contends that this setup was directed by LayerZero. According to the claim, LayerZero stated in February 2024 that the draft code was "good" and that there was "[n]o problem" with using the default configuration. In March 2024, they explicitly instructed Evercrest to implement a 1-of-1 configuration with LayerZero’s verifier. By January 2025, LayerZero indicated that even if a verifier was compromised, it would only fail to verify a message correctly.

The claim also mentions that LayerZero had warned another developer, USDT0, about risks associated with its default verifier configurations in late 2024 or early 2025, which led that developer to create its own. However, Evercrest claims it did not receive similar warnings.

Myriad: Where does Ethereum go next? Click to make your prediction.

The exploit originated within LayerZero itself. On March 6, an attacker installed malware on a LayerZero developer's computer, subsequently manipulating LayerZero’s nodes to provide false data to its verifier. On April 18, the attacker disabled third-party nodes used by the verifier, misinforming it that 116,500 rsETH had been locked on Unichain when, in fact, it had not. With only one verifier required, tokens were minted without backing. Evercrest claims to have halted the bridges within an hour and prevented a second attack.

The defamation allegations focus on the aftermath. LayerZero's incident report stated that the single-verifier setup contradicted a multi-DVN model it had "consistently recommended to all integration partners," with Pellegrino commenting that "[n]obody should be relying on sole DVN." Shortly after, the filing notes, LayerZero acknowledged it had "made a mistake by allowing [its] DVN to act as a 1-of-1 DVN for high-value transactions."

Evercrest is seeking damages that include a 2,000 ETH contribution to restore rsETH's backing, over $650 million withdrawn since the exploit, and a decline in the KERNEL token that attracted warnings from regulators and exchanges.

Pellegrino stated on Twitter that the lawsuit "continues to be meritless" and expressed his intent to defend himself in Vancouver. None of the claims have yet been adjudicated in court, and no formal response to the lawsuit has been filed.