Evercrest Technologies filed in the Supreme Court of British Columbia, alleging LayerZero approved its single-verifier bridge configuration in writing and warned another integrator about the same risk without warning Kelp. The claim adds a defamation count over LayerZero's post-exploit statements and seeks Evercrest's own losses rather than the full $292 million.
Evercrest Technologies, the company behind Kelp DAO, filed a notice of civil claim against LayerZero Labs and co-founder Bryan Pellegrino in the Supreme Court of British Columbia on Thursday, a little over five months after an attacker drained 116,500 rsETH from a bridge that ran on LayerZero's messaging layer. The claim pleads negligent misrepresentation, negligence and defamation, and seeks aggravated and punitive damages.
Its central allegation is that LayerZero approved the configuration it later blamed. The Block reports that LayerZero told Evercrest on February 2, 2024 that there was "no problem" with the default verifier configuration, and on March 21, 2024 directed it to use the same 1-of-1 setup as another bridge. Unchained, which reviewed the filing, describes written approvals in February 2024, March 2024 and January 2025, and says the claim alleges LayerZero warned the developer of USDT0 about configuration risk without giving Kelp the same warning. MiningPool has not read the notice of civil claim, and the allegations here are as described by outlets that have.
That allegation goes directly at the position LayerZero took in public. Its post-mortem in April pinned the exploit on Kelp's single-verifier setup, calling the breach isolated entirely to Kelp's rsETH configuration and a direct consequence of it, while Kelp said it had been running LayerZero's own defaults. What the claim adds to that exchange is dates and documents, and a forum in which both sides have to produce them.
The defamation count has no analogue in April. It targets Pellegrino's posts on X and Telegram along with LayerZero's own post-exploit statement, including language Unchained quotes as saying Kelp's setup "directly contradicts the multi-DVN redundancy model that LayerZero has consistently recommended to all integration partners." A negligence claim asks who was responsible for the loss. The defamation claim asks whether LayerZero's public account of who was responsible was itself actionable, and it is where the aggravated and punitive damages are directed.
The claim also starts the attack earlier than the exploit. Two accounts of the filing, Unchained's and crypto.news's, put the first intrusion on March 6, when an attacker social-engineered a LayerZero developer and obtained credentials, followed by tampering with RPC nodes and a denial-of-service attack on an outside RPC provider that forced a failover through the compromised path. That leaves roughly six weeks between the initial compromise and the forged message on April 18 that released the funds, and it matches what LayerZero itself described in April: nodes running malicious software that reported false data to the verifier while feeding accurate data to every other observer.
The money does not line up the way the headline figure suggests. The exploit took 116,500 rsETH, worth about $292 million and around 18 percent of the token's circulating supply at the time, and two further drain attempts reverted against contracts Kelp froze 46 minutes in. What Evercrest claims for itself is smaller. Unchained describes the damages sought as tens of millions of dollars without a single figure attached, which is a claim for the company's own losses rather than for the full amount taken from the bridge. The same account puts about $650 million of user withdrawals from Kelp since the exploit, measured at current ether prices, and says Kelp deployed 2,000 ether to restore rsETH's backing.
Pellegrino answered on X: "The claim continues to be meritless." He said he would defend himself in Vancouver. LayerZero's position since April has been that Kelp deployed multi-verifier defaults first and moved to the single-verifier configuration on its own, and it has said its verifier will not act as the sole required attestor on a channel.
The suit arrives with the contagion largely settled. A $303 million coalition of lenders and protocols published a plan to liquidate the attacker's position at the end of April, and Aave restored WETH loan-to-value limits across six networks in May, which closed out the second phase of the recovery. What the litigation covers is the part the recovery did not reach, and the reputational damage Evercrest says LayerZero's statements caused in the weeks afterward.
No hearing date has been reported, and nothing in a pleading has been tested. What the filing changes is the venue. The question of who chose Kelp's bridge configuration, argued in April through competing statements, now belongs to a court in Vancouver.