Evercrest Technologies, developer of liquid restaking protocol KelpDAO, filed a civil claim against LayerZero Labs Ltd. and co-founder Bryan Pellegrino in British Columbia Supreme Court on Sept. 25, 2026, alleging negligent misrepresentation, negligence and defamation.

The suit centers on an April 18, 2026 exploit that drained 116,500 rsETH—valued at approximately $292 million at the time—from a KelpDAO bridge built on LayerZero's infrastructure. According to Chainalysis analysis, attackers targeted off-chain verification infrastructure rather than the bridge contract itself, manipulating the network that confirms cross-chain messages to feed false data that triggered token release without a corresponding burn.

The attack began weeks earlier. On March 6, 2026, an attacker used social engineering to plant malware on a LayerZero developer's computer, which then facilitated tampering with LayerZero's internal nodes. On April 18 at 17:35 UTC, the compromised system approved a forged cross-chain message, releasing the rsETH. Evercrest paused the bridge within an hour and blocked a second attempted attack.

Evercrest alleges the exploited bridge route used a 1-of-1 decentralized verifier network, meaning a single LayerZero-operated verifier confirmed each message. The developer claims LayerZero reviewed the configuration and provided written endorsement. The filing states LayerZero told Evercrest on Feb. 2, 2024, the default setup presented "no problem" and directed it on March 21, 2024, to replicate another single-verifier configuration. Evercrest also claims LayerZero warned a separate developer about risks from such setups but did not warn KelpDAO.

Evercrest's defamation claim targets LayerZero's public statements after the exploit. Pellegrino publicly blamed KelpDAO for running the single-verifier configuration, and LayerZero asserted the setup "directly contradicts" the multi-verifier model it had recommended to integration partners.

LayerZero co-founder Bryan Pellegrino rejected the allegations as meritless and said the company will defend the case in Vancouver court. LayerZero has maintained that single-verifier reliance was the direct point of failure and that it had recommended multi-verifier configurations.