NewsLayer.com
NewsLayer PulseLIVEBTC$83,839-0.61%ETH$2,684-0.13%SOL$121.63+4.14%XRP$1.56+2.01%DOGE$0.0978+2.08%ADA$0.2544+2.78%Total Cap$2.86T-0.02%Layer Index43 Neutral

Web3

breaking

KelpDAO Developer Sues LayerZero Over $292M Bridge Exploit

Evercrest says LayerZero approved the single-verifier configuration in writing multiple times, then warned a different developer about it.

Decrypt Agent

Publisher Decrypt

Sep 25, 2026 at 11:09 AM UTC · 2 分で読める

KelpDAO Developer Sues LayerZero Over $292M Bridge Exploit
NewsLayer editorial artwork
翻訳中…

In brief

  • Evercrest Technologies has filed a civil claim against LayerZero, its Canadian arm and co-founder Bryan Pellegrino in the Supreme Court of British Columbia.
  • The claim alleges negligent misrepresentation, negligence and defamation over April's $292 million exploit.
  • It says the attack began with malware on a LayerZero developer's computer six weeks before any funds moved.

The company behind KelpDAO has sued LayerZero and its chief executive over the exploit that drained $292 million from the restaking protocol in April, alleging LayerZero endorsed in writing the exact bridge configuration it later blamed for the loss.

Evercrest Technologies filed the notice of civil claim in the Supreme Court of British Columbia on Wednesday, naming LayerZero Labs Ltd., LayerZero Labs Canada Inc. and co-founder Bryan Pellegrino, who is sued personally over posts on Telegram and X. It pleads negligent misrepresentation, negligence and defamation, and seeks aggravated and punitive damages.

KelpDAO's bridges ran a 1-of-1 setup, meaning LayerZero's own verifier network was the only party confirming that tokens had been locked on one chain before equivalent tokens were minted on another.

Evercrest says that was LayerZero's instruction. LayerZero told it in February 2024 that its draft code was "good" and that there was "[n]o problem" using the default configuration, according to the filing, and in March 2024 explicitly directed it to use a 1-of-1 setup with LayerZero's own verifier. In January 2025, LayerZero said that even if a verifier were compromised, the most it could do was fail to verify a message correctly.