TL;DR

  • Evercrest Technologies, the company behind KelpDAO, has filed a civil claim against LayerZero entities and co-founder Bryan Pellegrino.
  • The lawsuit concerns the April exploit that drained 116,500 rsETH, worth about $292 million at the time.
  • KelpDAO alleges LayerZero reviewed and endorsed the bridge configuration later blamed for the attack; those claims have not been proven in court.

The company behind KelpDAO has taken its dispute with LayerZero into court, filing a civil claim over the April bridge exploit that cost the restaking protocol roughly $292 million.

Evercrest Technologies filed the case in the Supreme Court of British Columbia against LayerZero Labs Ltd., LayerZero Labs Canada Inc. and co-founder Bryan Pellegrino.

The allegations include negligence, negligent misrepresentation and defamation.

The Dispute Centers On A 1-of-1 Security Configuration

The underlying exploit involved 116,500 rsETH moved through a bridge connecting KelpDAO infrastructure with Unichain.

At the time of the attack, the assets were worth approximately $292 million.

A major point of disagreement since then has been the bridge’s security configuration.

KelpDAO alleges LayerZero reviewed and endorsed a setup using a single Decentralized Verifier Network, or DVN, rather than warning the project that the configuration created a dangerous single point of failure.

The lawsuit further alleges that LayerZero later blamed KelpDAO for using that design.

Those are allegations from Evercrest’s court filing.

LayerZero has not been found liable, and the filing does not establish that its account of the events is correct.

That distinction is especially important in a dispute where the technical responsibility for a bridge failure is itself part of the case.

Bridge Security Is Becoming A Legal Question Too

Cross-chain security failures have typically been treated as technical incidents.

A bridge gets exploited, investigators trace the funds, developers patch the vulnerability and protocols argue over who configured what.

The KelpDAO case could push that discussion into a different arena.

If infrastructure providers review or recommend security configurations used by third-party applications, courts may eventually have to decide what responsibility comes with that advice.

That has implications well beyond KelpDAO and LayerZero.

Interoperability systems depend on protocols integrating software and trust assumptions they did not design entirely themselves.

When hundreds of millions of dollars move through those systems, disagreements about who understood the risk can quickly become more than engineering disputes.

For now, the lawsuit marks the beginning of that process rather than the conclusion.

The fight over who bears responsibility for it is only now moving into court.

This article was written by the News Desk and edited by Samuel Rae.