Evercrest Sues LayerZero Over April Attack on rsETH Bridge
Evercrest Technologies, the company behind KelpDAO, has filed a civil lawsuit in British Columbia against LayerZero Labs and co-founder Bryan Pellegrino. The dispute concerns the April attack on the rsETH bridge.

Evercrest’s lawsuit against LayerZero concerns the April attack on the rsETH bridge, during which 116,500 rsETH worth approximately $292 million at the time of the incident was released. KelpDAO publicly announced that Evercrest Technologies, the entity behind the project, had filed a civil lawsuit in the Canadian province of British Columbia against LayerZero Labs and its co-founder Bryan Pellegrino.
The filing moves the previously public dispute over the bridge’s technical configuration and responsibility for its security into court proceedings. LayerZero calls the lawsuit baseless. The court has not yet ruled on the matter.
What Happened in the Attack on the rsETH Bridge
The incident occurred on April 18, 2026. According to LayerZero’s final report, LayerZero RPC infrastructure used by its decentralized verifier network (DVN) was compromised. This infrastructure was part of the message-verification process for the rsETH bridge.
LayerZero’s report also stated that the application used a configuration with a single mandatory DVN, a 1-of-1 model. This setup created a single mandatory point in the process of verifying messages between networks. After the incident, LayerZero stopped signing channels with a 1-of-1 configuration as the sole mandatory verifier.
According to available information, the incident was not characterized as a confirmed rsETH smart-contract bug. The core of the case is the compromise of off-chain infrastructure and a verification configuration with a single mandatory provider.
Evercrest’s Lawsuit Against LayerZero and the Disputed Configuration
According to a KelpDAO statement, Evercrest claims that LayerZero approved the configuration in writing, which it later described as the source of a single point of failure after the attack. However, the full complaint could not be independently verified from a publicly available court document.
The dispute is also expected to concern whether LayerZero sufficiently warned about the risks of such a configuration, whether it should have rejected the setup, and what legal responsibility an infrastructure provider may bear for an application’s security decisions. These are the parties’ claims, not court findings.
The earlier public dispute between the parties also concerned whether a configuration with a single verifier was a recommended or default setting. The new proceedings may provide more detailed information about communications between Evercrest and LayerZero, security-architecture recommendations, and any approval of the 1-of-1 model.
Why the Dispute Matters for Cross-Chain Infrastructure
Bridges transfer assets or messages between blockchains, and their security depends not only on smart contracts but also on how off-chain messages are verified. The rsETH case therefore focuses on the interface between a DeFi application and its verification-infrastructure provider.
Evercrest’s lawsuit against LayerZero may clarify the contractual and operational expectations between projects using bridge infrastructure and its providers. It is not yet known, however, what specific legal claims Evercrest is pursuing or what defenses LayerZero and Pellegrino will present.
What to Watch Next
- publication of the original notice of civil claim and the exact wording of Evercrest’s claims,
- LayerZero Labs’ and Bryan Pellegrino’s formal response to the filing in British Columbia,
- any court findings about communications, recommendations, and approval of the 1-of-1 configuration,
- further information about the recovery or return of assets released during the attack.
Sources
- KelpDAO statement via Outposts – Reports KelpDAO’s announcement of the lawsuit against LayerZero and Bryan Pellegrino.
- LayerZero Labs KelpDAO Incident Report – Confirms the scope of the April incident, the compromise of RPC infrastructure, and the subsequent policy change for configurations with a single DVN.
- Decrypt – Corroborates the lawsuit filing and describes Evercrest’s claim that the configuration was approved in writing.
- CoinDesk – Documents the parties’ earlier dispute over whether the single-verifier configuration was recommended or the default setting.
Verified and updated: September 25, 2026 15:26



