Five months after attackers used a compromised Layerzero verifier to release 116,500 rsETH worth about $292m, KelpDAO’s parent company has taken the dispute to court.
Evercrest Technologies Inc. filed a civil claim in British Columbia on 24 September against Layerzero Labs and its chief executive, Bryan Pellegrino. The case centres on whether responsibility lies with Layerzero’s security infrastructure or Kelp’s decision to use a single verifier for high-value transfers.
The exploit happened at 17:35 UTC on 18 April. Kelp’s rsETH bridge used Layerzero technology to move tokens from Unichain to Ethereum, with a 1-of-1 decentralised verifier network (DVN) checking messages.
Attackers submitted a forged message claiming that 116,500 rsETH had been burned or locked on another blockchain. The verifier accepted it and the bridge released the tokens on Ethereum, despite no corresponding burn. Its holdings dropped from 116,723 rsETH to 223 in one block, representing about 18% of the circulating supply.
Much of the stolen rsETH was deposited into Aave V3 on Ethereum and Arbitrum. The attacker distributed the tokens among seven addresses, depositing about 89,567 rsETH and borrowing roughly 82,650 wrapped ether (WETH) and 821 wrapped staked ether (wstETH). Aave’s Protocol Guardian began freezing rsETH and wrsETH reserves at about 19:00 UTC.
Kelp paused its contracts around 46 minutes after the initial drain and prevented a second forged transaction involving about 40,000 rsETH, estimated to be worth $95m-$100m. Estimates of Aave’s resulting bad debt ranged from $123.7m to $230.1m.
Chainalysis concluded that Kelp’s token contracts had not malfunctioned and that the false information had entered the process off-chain. Layerzero later said an attacker had socially engineered a developer on 6 March, stolen session credentials and accessed its RPC cloud infrastructure. Compromised internal nodes supplied false data after external RPC providers were targeted by a distributed denial-of-service attack.
Layerzero’s incident report, citing Mandiant and Crowdstrike, attributed the intrusion to Trader-Traitor, also known as UNC4899, a North Korea-linked cluster associated with the wider Lazarus Group. That remains an intelligence assessment, not a court finding.
Kelp said on X: “Today we filed a lawsuit against Layerzero and its co-founder, Bryan Pellegrino, to right the wrongs associated with the exploit of rsETH’s Layerzero bridge earlier this year.”
It alleges Layerzero failed to disclose risks, protect its infrastructure and prevent the compromise. Kelp also says the 1-of-1 setup was Layerzero’s documented default and had been approved in writing. It cited Dune data suggesting about 47% of Layerzero applications, covering more than 1,200 contracts, used that arrangement.
Layerzero says it recommended multiple verifiers and has blamed the single-verifier configuration for creating the point of failure. Pellegrino called the claim “meritless” and wrote: “The claim continues to be meritless, will meet them in Vancouver and defend myself accordingly.”
After the incident, Layerzero apologised for allowing its DVN to operate as 1/1 for high-value transactions and moved towards multi-verifier defaults. Kelp announced plans to transfer rsETH from Layerzero’s OFT system to Chainlink’s CCIP and CCT infrastructure.
Arbitrum’s Security Council froze about 30,765.67 ETH, then worth roughly $71m, while Aave, Lido, Ether.fi, Ethena, Mantle, Consensys and Joe Lubin supported recovery efforts through DeFi United. Kelp later said minting, redemptions and bridging had resumed.
The claim is listed at Vancouver Law Courts under file number 267169, although the full notice has not been made public. The court has not yet determined liability or the damages sought.
