Loading prices…
🩸BEARISH

LayerZero Faces $292M KelpDAO Lawsuit as $14.5B Moves

The case puts provider guidance and customer configuration at the center of bridge security, as major projects shift assets toward Chainlink CCIP.

Evercrest Technologies, the company behind KelpDAO, is suing LayerZero Labs, its Canadian affiliate and CEO Bryan Pellegrino in British Columbia over April’s $292 million rsETH exploit. The claim alleges negligence, negligent misrepresentation and defamation, and says Kelp users have withdrawn more than $650 million since the attack. By Aug. 4, projects tied to about $14.5 billion in assets had announced moves from LayerZero to Chainlink CCIP, nearly 50 times the amount stolen. Pellegrino has called the suit meritless.

Why it matters

The dispute turns on two security layers that failed in different ways. Attackers compromised LayerZero’s RPC environment after socially engineering a developer, then poisoned internal nodes and disrupted an external provider. LayerZero’s verifier consequently approved a forged transfer, and 116,500 rsETH left Kelp’s bridge. Kelp’s bridge required only that single verifier, so no independent verifier was required to reject the false message.

Evercrest alleges LayerZero reviewed and approved the single-verifier configuration in writing, including telling Kelp in February 2024 there was “no problem” with a default setup. LayerZero says Kelp chose to move from a two-of-two configuration to one-of-one. Those claims remain untested in court. The case could help define responsibility when a customer configures a system but a provider advises on the setup and operates critical infrastructure.

Market impact

The migration tally measures announced asset value, not completed transfers. BitGo represents about $7.4 billion of the Aug. 4 total, with WBTC its largest component; BitGo named CCIP its exclusive cross-chain provider for WBTC and the default for future BitGo-issued assets. Kelp’s migration is still underway. Wyoming’s state-issued FRNT token also fully moved off LayerZero and made CCIP its exclusive provider.

LayerZero has since stopped signing on channels where its verifier is the sole required signer and raised default pathways to a minimum of three verifiers. If Kelp substantiates its approval allegations, providers may face greater legal exposure for endorsing custom security configurations. The court’s treatment of that responsibility could shape how bridge operators and other infrastructure providers set defaults, document risk and serve institutional customers.

Related tokens
$WBTC

Frequently asked questions

  1. How did the rsETH exploit drain funds from KelpDAO’s bridge?

    Attackers compromised LayerZero’s RPC environment and poisoned data used by its verifier. Kelp’s bridge required only that verifier, which approved a forged transfer of 116,500 rsETH.

  2. What does KelpDAO allege LayerZero did before the exploit?

    Evercrest alleges LayerZero reviewed and approved the single-verifier setup in writing, including saying there was “no problem” with a default configuration. LayerZero disputes responsibility and says Kelp chose the setup.

  3. How much value has been announced for migration from LayerZero?

    Projects tied to about $14.5 billion in assets had announced moves to Chainlink CCIP by Aug. 4. That figure is announced asset value, not a measure of completed transfers.

  4. What role does BitGo play in the migration?

    BitGo accounts for about $7.4 billion of the Aug. 4 tally, with WBTC its largest component. It named CCIP its exclusive cross-chain provider for WBTC and the default for future BitGo-issued assets.

  5. What security changes has LayerZero made since the attack?

    LayerZero now refuses to sign on channels where its verifier is the only required signer and has raised default pathways to a minimum of three verifiers.

Source attribution
Aggregated from CryptoSlate · Verified · Last refreshed 1h ago
Open original →