Escalation in Web3: Evercrest Technologies Takes $292 Million KelpDAO Bridge Dispute with LayerZero to Court
By the News Desk | Edited by Samuel Rae
Published by NewsBTC
Main Facts
The legal battle lines between prominent Web3 infrastructure providers have officially been drawn in a Canadian court, transforming a catastrophic technical exploit into a high-stakes judicial proceeding. Evercrest Technologies, the development company behind the prominent restaking protocol KelpDAO, has initiated a formal civil lawsuit against LayerZero Labs Ltd., LayerZero Labs Canada Inc., and LayerZero co-founder Bryan Pellegrino.
Filed in the Supreme Court of British Columbia, the lawsuit stems from a devastating bridge exploit that occurred in April, resulting in the theft of approximately $292 million worth of digital assets. The core of the legal complaint centers on a disastrous security configuration involving 116,500 units of rsETH (KelpDAO’s liquid restaking token) that were moved through a cross-chain bridge connecting KelpDAO’s infrastructure to Unichain.
According to Evercrest Technologies’ court filings, the dispute is not merely about the execution of the exploit itself, but about the advisory role, due diligence, and shared accountability surrounding the bridge’s architecture. Evercrest alleges that LayerZero reviewed and actively endorsed a high-risk security configuration—specifically, a 1-of-1 security setup utilizing a single Decentralized Verifier Network (DVN)—without adequately warning the KelpDAO team that the setup created a catastrophic single point of failure.
Furthermore, the lawsuit expands beyond simple contract or negligence claims, incorporating allegations of negligent misrepresentation and defamation. Evercrest contends that in the aftermath of the multi-million-dollar heist, LayerZero and its leadership publicly shifted the narrative, improperly casting blame onto KelpDAO for deploying the very architectural design that LayerZero allegedly greenlit.
As this case proceeds through the British Columbia judicial system, it marks a pivotal moment for the decentralized finance (DeFi) industry. Historically, multi-million-dollar cross-chain exploits have been handled strictly within the realm of on-chain forensics, white-hat negotiations, or quiet protocol-level settlements. By bringing the dispute to a traditional court of law, Evercrest is forcing a legal examination of where developer advisory responsibility ends and protocol liability begins in the interconnected world of blockchain interoperability.
Chronology of Events
To understand how a technical exploit in April evolved into an international civil lawsuit, it is essential to trace the timeline of events leading up to the filing in the Supreme Court of British Columbia.
Phase 1: Integration and Architecture Design
Months prior to the incident, KelpDAO sought to expand its ecosystem footprint by leveraging cross-chain interoperability solutions to connect its rsETH restaking infrastructure with emerging networks like Unichain. To achieve seamless asset transfers, the protocol integrated with LayerZero’s cross-chain messaging and bridging framework. During this integration phase, the configuration of the bridge’s security modules—specifically the Decentralized Verifier Networks (DVNs) responsible for validating cross-chain transactions—was established. According to Evercrest’s legal filings, this configuration involved a 1-of-1 setup, meaning a single verifier signature was sufficient to validate and execute cross-chain asset movements. Evercrest maintains that LayerZero’s technical teams reviewed and endorsed this specific framework.
Phase 2: The April Exploit and $292 Million Loss
In April, the security assumptions underlying the bridge were severely tested and ultimately broken. Attackers exploited the vulnerability inherent in the 1-of-1 DVN configuration, successfully intercepting and redirecting 116,500 rsETH. At the time of the breach, the stolen assets were valued at approximately $292 million. The swiftness and scale of the exploit sent shockwaves through the restaking and broader DeFi ecosystem, immediately halting cross-chain operations and triggering emergency response protocols across both the KelpDAO and LayerZero communities.
Phase 3: The Blame Game and Public Fallout
Immediately following the exploit, a war of words erupted between stakeholders, developers, and community members regarding who bore ultimate responsibility for the architectural flaw. While on-chain sleuths and security firms traced the drained funds, executive leadership and community representatives from both sides began offering competing narratives. KelpDAO argued that it relied on LayerZero’s technical guidance and security validation when deploying the bridge. Conversely, public commentary and statements originating from the LayerZero ecosystem appeared to point the finger back at KelpDAO, asserting that the protocol operators had improperly configured their own security parameters.
Phase 4: Legal Escalation in British Columbia
With reputational damage mounting and hundreds of millions of dollars in user funds unaccounted for, informal discussions broke down. Recognizing that remediation and consensus were unattainable outside of a binding legal framework, Evercrest Technologies elected to take formal legal action. By filing the lawsuit in the Supreme Court of British Columbia—where LayerZero maintains corporate entities (LayerZero Labs Canada Inc.)—Evercrest formally transitioned the dispute from a Twitter/X debate and Discord argument into a formal judicial proceeding complete with formal discovery, legal briefs, and ultimately, judicial oversight.
Supporting Data and Technical Architecture
The technical core of the lawsuit hinges on complex cross-chain infrastructure mechanics that are rarely scrutinized in traditional courtrooms. To evaluate the merits of Evercrest’s claims, industry analysts and legal experts must examine the specific engineering components that failed during the April incident.
The Anatomy of the Bridge and rsETH
KelpDAO operates as a leading liquid restaking protocol, allowing users to deposit underlying liquid staking tokens (LSTs) such as stETH to mint rsETH, which accrues restaking rewards across various networks. To maximize utility, rsETH needs to move fluidly across layer-2 rollups and application-specific chains like Unichain. This cross-chain mobility is facilitated by messaging protocols like LayerZero, which allow smart contracts on one blockchain to securely communicate with contracts on another.
The 1-of-1 DVN Security Configuration
In LayerZero’s architecture, security is modular. Developers can configure Decentralized Verifier Networks (DVNs) to independently verify cross-chain messages. A robust configuration typically requires a M-of-N threshold—for instance, requiring multiple independent security entities (such as Chainlink, Google Cloud, or specialized security providers) to sign off on a transaction before it is deemed valid.
In the case of the compromised KelpDAO bridge, the configuration was set to a 1-of-1 security model. This meant that validation relied entirely on a single verifier node or pathway. If that single entity was compromised, manipulated, or misconfigured, the entire security perimeter of the bridge collapsed.
- The Asset Scale: 116,500 rsETH.
- Valuation at Time of Exploit: ~$292 million USD.
- Vulnerability Point: Single point of failure via the 1-of-1 DVN setup.
- Disputed Responsibility: Evercrest claims LayerZero reviewed and approved this exact setup; LayerZero maintains that protocol implementers hold ultimate configuration authority.
It is critical to note that as of this filing, LayerZero has not been found legally liable by any court, and the allegations put forward by Evercrest Technologies represent only one side of a highly contentious technical disagreement. Establishing liability will require expert cryptographic and software engineering testimony to determine standard practices in cross-chain bridge deployments.
Official Responses and Legal Claims
The lawsuit filed by Evercrest Technologies in the Supreme Court of British Columbia outlines specific, severe legal counts against LayerZero Labs Ltd., LayerZero Labs Canada Inc., and Bryan Pellegrino. While formal statements from both parties continue to evolve as legal representation prepares defense and plaintiff briefs, the foundational pillars of the complaint are clear.
The Core Allegations from Evercrest Technologies
- Negligence: Evercrest alleges that LayerZero failed in its professional duty of care as a foundational infrastructure provider. By allegedly reviewing and endorsing a dangerously fragile 1-of-1 DVN security setup, LayerZero allegedly exposed its integration partners to existential risk.
- Negligent Misrepresentation: The lawsuit asserts that LayerZero provided misleading assurances or representations regarding the safety, robustness, and adequacy of the bridge configuration during the onboarding and integration phases.
- Defamation: Beyond the technical failure of the bridge, Evercrest claims that public statements made by LayerZero and its co-founder, Bryan Pellegrino, in the aftermath of the exploit unjustly blamed KelpDAO. Evercrest argues these statements caused severe reputational harm to the protocol, its developers, and its brand equity in an intensely competitive market.
The LayerZero Perspective and Industry Implications
While LayerZero has not yet submitted its formal statement of defense in court, the protocol’s general defensive posture in similar historical disputes relies heavily on the principle of shared responsibility and client configuration autonomy. In decentralized ecosystems, infrastructure providers typically supply the plumbing (the SDKs, messaging protocols, and optional modules), but the final deployment parameters, risk thresholds, and security configurations are executed by the application developers themselves.
If infrastructure providers were held strictly liable for every developer configuration error or weak security threshold chosen during integration, the cost and legal risk of building interoperable blockchain systems would skyrocket. Conversely, if infrastructure providers can actively consult on, review, and endorse risky configurations without facing any legal recourse when those endorsements fail catastrophically, protocols have little judicial recourse when major exploits occur. This tension forms the ideological and legal core of the entire case.
Implications for the Broader Web3 Ecosystem
The civil lawsuit between Evercrest Technologies and LayerZero transcends a mere private corporate disagreement. It establishes a groundbreaking legal precedent that could permanently alter how cross-chain bridges, restaking protocols, and modular blockchain infrastructure are built, reviewed, and deployed.
1. The Legalization of Smart Contract Disputes
For over a decade, the crypto industry operated under an informal, albeit volatile, code-is-law ethos where hacks were treated as technical anomalies resolved through white-hat bounties, asset freezes, or community governance votes. By dragging a complex multi-million-dollar cross-chain exploit into a traditional courtroom, Evercrest is signaling a new era. Web3 projects are increasingly willing to utilize civil courts, international jurisdictions, and traditional tort law to recover losses and assign blame when technical safeguards fail.
2. Redefining the Duty of Care for Infrastructure Providers
Interoperability protocols like LayerZero, Axelar, and Wormhole act as the connective tissue of the multi-chain universe. They integrate with hundreds of third-party applications, decentralized exchanges, and lending markets. If courts determine that providing technical reviews or security recommendations creates a legal "duty of care" that carries tort liability, infrastructure providers will be forced to drastically alter their onboarding processes. This could manifest as:
- Mandatory, highly restrictive out-of-the-box security minimums that prevent developers from choosing risky setups like 1-of-1 configurations.
- Extensive, formal legal disclaimers and liability waivers embedded in developer SDK agreements.
- Exponentially higher integration costs as infrastructure providers purchase massive professional liability (Errors and Omissions) insurance policies.
3. Increased Scrutiny on Modular Security
The incident highlights the inherent dangers of modular blockchain design. While modularity allows protocols to compose services rapidly, it diffuses accountability. When an exploit occurs across a multi-layered stack involving a restaking protocol (KelpDAO), a bridging layer (LayerZero), and an execution environment (Unichain), determining the weakest link is an engineering nightmare—and now, a legal labyrinth.
4. What Lies Ahead
The litigation in the Supreme Court of British Columbia is only in its infancy. Over the coming months and years, legal teams will subpoena internal communications, chat logs, technical documentation, and code reviews from both Evercrest and LayerZero. Expert witnesses from across the cryptographic community will be called upon to testify regarding industry standards for DVN configurations and bridge security.
Regardless of the ultimate verdict or settlement, the filing of this lawsuit permanently changes the risk calculus for Web3 developers. The days of treating cross-chain infrastructure integration as a purely technical exercise are officially over; interoperability is now inextricably tied to legal liability, corporate accountability, and the cold reality of courtroom litigation.
Disclaimer: The allegations detailed in this article are derived exclusively from court filings in the Supreme Court of British Columbia. LayerZero Labs, LayerZero Labs Canada Inc., and Bryan Pellegrino have not been found legally liable for the claims made by Evercrest Technologies. This report is for informational purposes only and does not constitute legal or financial advice.
