Tag: Bryan Pellegrino

  • KelpDAO Developer Sues LayerZero, CEO Over $292M Exploit and Blame-Shifting

    KelpDAO Developer Sues LayerZero, CEO Over $292M Exploit and Blame-Shifting

    Key Highlights

    • Evercrest Technologies, developer of KelpDAO, filed a lawsuit on September 24 against LayerZero Labs, its Canadian entity, and CEO Bryan Pellegrino over the April 2026 rsETH bridge exploit that caused approximately $292 million in losses.
    • The complaint alleges the exploit stemmed from a compromised LayerZero developer device, poisoned RPC data, and a 1-of-1 Decentralized Verifier Network (DVN) configuration that Evercrest claims LayerZero reviewed and instructed them to implement.
    • Evercrest is seeking damages covering a 2,000 ETH recapitalization, over $650 million in user withdrawals, lost fee revenue, KERNEL token declines, the shutdown of its sbUSD vault, a delayed stablecoin product, legal costs, and reputational harm.

    Evercrest Technologies Sues LayerZero Labs Over $292 Million rsETH Bridge Exploit

    Evercrest Technologies, the entity behind the KelpDAO liquid restaking protocol, has initiated legal action against LayerZero Labs, its Canadian subsidiary, and Chief Executive Officer Bryan Pellegrino. The complaint, published on September 24, centers on the April 18, 2026 exploit of KelpDAO’s rsETH bridge on Unichain, which resulted in approximately $292 million in losses. Evercrest contends the incident was not caused by a vulnerability in its own smart contracts but rather by a combination of poisoned RPC data, a compromised LayerZero developer machine, and a single-verifier DVN architecture that LayerZero allegedly endorsed.

    Attack Timeline and Technical Root Cause

    According to the filing, the attack chain began on March 6, 2026, when an attacker compromised a LayerZero developer’s machine. In April, the threat actor targeted the RPC infrastructure underpinning LayerZero’s Decentralized Verifier Network. The manipulated RPC endpoints allegedly caused LayerZero’s sole DVN to falsely attest that 116,500 rsETH had been locked on Unichain, despite no such lock occurring on the source chain. Because LayerZero served as the exclusive verifier for the Unichain Bridge, this false attestation triggered the minting of $292 million worth of rsETH on Ethereum mainnet.

    Evercrest states it detected the anomalous activity within one hour, immediately suspended its LayerZero-powered bridges, froze the attacker’s wallet, and prevented a second minting attempt of 40,000 rsETH. The rapid response limited further damage, but the initial exploit had already executed.

    Dispute Over Bridge Configuration and Responsibility

    A central point of contention in the lawsuit is the bridge’s verification architecture. Evercrest asserts that LayerZero reviewed and endorsed KelpDAO’s bridge configuration and explicitly instructed the team to operate its own DVN in a 1-of-1 setup. The complaint alleges that after the exploit, LayerZero shifted its public narrative, blaming KelpDAO’s single-verifier design. CEO Bryan Pellegrino reportedly stated that applications should not rely on a sole DVN, a position Evercrest says contradicts LayerZero’s prior written guidance. Evercrest maintains it followed LayerZero’s documented instructions throughout the integration process.

    Today we filed a lawsuit against LayerZero and its co-founder, Bryan Pellegrino, to right the wrongs associated with the exploit of rsETH’s LayerZero bridge earlier this year. For more details, please refer to the statement below.https://t.co/gPQTPeM0Zh
    — Kelp (@KelpDAO) September 25, 2026

    Damages Sought and Operational Fallout

    The complaint itemizes extensive damages, including a 2,000 ETH recapitalization requirement, more than $650 million in user withdrawals following the incident, lost protocol fee revenue, declines in the KERNEL governance token, the forced shutdown of KelpDAO’s sbUSD vault, and the delay of a planned stablecoin product. Evercrest also cites legal expenses, migration costs to alternative infrastructure, and reputational harm to the protocol and its stakeholders.

    Why This Matters

    The lawsuit highlights growing tensions in the cross-chain infrastructure layer as protocols seek accountability for exploits involving interoperability messaging. LayerZero’s DVN model, which allows applications to configure their own verification quorums, places significant responsibility on both the infrastructure provider and the integrating team. This case may set a precedent for how liability is allocated when a messaging layer’s off-chain components—such as RPC endpoints and developer environments—are compromised, and whether written integration guidance creates enforceable obligations. The outcome could influence how DeFi protocols evaluate bridge risk, negotiate service-level agreements with messaging providers, and structure multi-verifier architectures going forward.

    Frequently Asked Questions

    What specific failures does Evercrest attribute to LayerZero?

    Evercrest alleges three interlocking failures: a compromised LayerZero developer device on March 6, 2026; poisoned RPC data fed to LayerZero’s Decentralized Verifier Network in April; and a 1-of-1 DVN configuration that LayerZero reportedly reviewed, endorsed, and instructed KelpDAO to implement for the Unichain Bridge.

    How did Evercrest respond to the exploit?

    Evercrest states it identified the attack within one hour, suspended all LayerZero bridges, froze the attacker’s wallet, and blocked a second minting attempt of 40,000 rsETH, preventing additional losses beyond the initial $292 million exploit.

    What damages is Evercrest seeking in the lawsuit?

    The complaint seeks recovery for a 2,000 ETH recapitalization, over $650 million in user withdrawals triggered by the incident, lost fee revenue, KERNEL token value declines, the shutdown of the sbUSD vault, a delayed stablecoin launch, legal and migration costs, and reputational harm to the KelpDAO protocol and Evercrest Technologies.