A $292 million crypto exploit that began with compromised off-chain infrastructure has moved from post-mortems and social media arguments straight into a courtroom.
Evercrest Technologies, the team behind KelpDAO, has filed a civil suit in the Supreme Court of British Columbia against LayerZero Labs and its CEO, Bryan Pellegrino. The lawsuit stems from an April exploit that drained 116,500 rsETH. KelpDAO alleges that LayerZero reviewed, endorsed, and directed the bridge configuration involved, failed to disclose key security risks, and later misrepresented Kelp’s role in public statements. LayerZero denies the claims, with Pellegrino calling the suit meritless.
While the allegations remain unproven, the case brings an existential question to the forefront of decentralized finance: When modular, third-party infrastructure fails, where does legal and technical liability actually sit?
The attack was not a conventional smart-contract flaw. The destination-side smart contracts executed exactly as designed. The failure occurred upstream in the data feeding them.
According to incident reports from Chainalysis and LayerZero, attackers compromised a LayerZero developer through social engineering to gain session credentials. From there, they accessed the RPC infrastructure feeding LayerZero’s Decentralized Verifier Network (DVN). The attackers poisoned RPC nodes, launched denial-of-service attacks against external RPCs, and fed manipulated data directly to the verifier.
The verifier accepted the false data and signed off on a forged cross-chain message confirming a token burn on the source chain that never occurred. The destination bridge accepted the signature and minted unbacked tokens. The on-chain math checked out; the off-chain reality was entirely fabricated.
Cross-chain architectures rely on verifiers to validate state changes between independent networks. KelpDAO’s rsETH bridge was running on a 1-of-1 configuration using LayerZero Labs' sole DVN.
Because only one approval was required, compromising that single pipeline allowed the attacker to drain the bridge. Had a multi-DVN setup been used, an independent verifier would have rejected the mismatch.
The disagreement over why this configuration existed forms the heart of the legal battle:
KelpDAO’s Position: Kelp argues it did not select the 1-of-1 setup in isolation. The lawsuit cites written exchanges across 2024 and early 2025 alleging LayerZero reviewed, approved, and directed the deployment. Kelp further claims that LayerZero warned other integrators about default setup risks while leaving Kelp in the dark.
The Industry Context: Data from Dune Analytics showed that roughly 47% of LayerZero OApp contracts were using a 1-of-1 DVN setup at the time. While this configuration alone does not guarantee vulnerability, it challenges the narrative that Kelp had opted into an obscure, abnormal arrangement.
LayerZero’s Position: LayerZero initially pointed directly to the 1-of-1 setup, maintaining that its messaging protocol remained secure and that applications maintain full autonomy over their risk parameters.
The narrative shifted in May when LayerZero publicly conceded a misstep, admitting: “We made a mistake by allowing our DVN to act as a 1/1 DVN for high-value transactions.” LayerZero subsequently phased out solo-DVN support for its verifier. While this admission does not automatically imply legal negligence, it undermines clean boundaries between infrastructure provider and integrator.
Kelp managed to pause its contracts and stop an additional drain of 40,000 rsETH (worth ~$95 million at the time), but the initial $292 million loss rippled across DeFi.
Because rsETH serves as collateral across major money markets, the sudden injection of unbacked tokens forced platforms like Aave to evaluate potential bad-debt exposure. Composable architecture allows rapid innovation, but it also creates tight systemic coupling: an attack on a single developer machine can compromise an RPC node, corrupt a verifier, trick a bridge, and threaten collateral pools across unrelated protocols.
KelpDAO has since migrated its cross-chain messaging from LayerZero to Chainlink’s Cross-Chain Interoperability Protocol (CCIP).
Evercrest's suit covers negligence, negligent misrepresentation, and defamation. As the case proceeds, the court will have to determine:
Did LayerZero's explicit technical guidance constitute an endorsement of safety?
How much technical due diligence remains the non-delegable duty of an application developer?
Does offering an unsafe default configuration expose an infrastructure provider to liability?
In traditional finance, service agreements and regulatory frameworks clearly delineate vendor accountability. DeFi has historically operated under "code is law" and decentralized disclaimers.
The KelpDAO v. LayerZero lawsuit signals that the era of settling multi-million-dollar infrastructure failures exclusively through Discord post-mortems and social media statements is ending. As real capital flows into modular web3 networks, the infrastructure layers connecting smart contracts to off-chain reality will increasingly be held accountable in courts of law.