Evercrest Technologies Inc., the company that operates the liquid restaking protocol KelpDAO, filed a civil lawsuit in British Columbia, Canada, on September 24, 2026, against LayerZero Labs Ltd. and its co-founder and chief executive officer (CEO), Bryan Pellegrino. The claim relates to the April 18 exploit in which an attacker drained 116,500 rsETH, then worth about $292 million, through KelpDAO’s LayerZero-based bridge.
Evercrest is identified in KelpDAO’s terms of service and in a KernelDAO MiCA white paper as a Panama international business corporation. LayerZero Labs Ltd. is the British Virgin Islands company named in LayerZero’s terms of use. A related Canadian affiliate, LayerZero Labs Canada Inc., is federally registered in Vancouver, where Pellegrino is a director. KelpDAO is the liquid restaking product under the KernelDAO brand.
KelpDAO is a decentralized autonomous organization (DAO) that issues rsETH, a liquid restaking token representing Ether (ETH) restaked through its protocol. LayerZero is a cross-chain messaging protocol that allows applications to move messages and tokens between different blockchains.
Pellegrino Confirmed the Filing First
The first public confirmation came from the defendant, not the plaintiff. At 22:57:04 Coordinated Universal Time (UTC) on September 24, Pellegrino posted on X that Evercrest had filed a notice of civil claim against him and LayerZero that day. He described the claim as “meritless” and said he would “meet them in Vancouver” and defend himself.
A notice of civil claim is the document that starts a civil lawsuit in British Columbia’s courts. The British Columbia court services listing names Evercrest Technologies Inc. as the plaintiff and LayerZero Labs Ltd. on the defendant side, with the case recorded at Vancouver Law Courts under file number 267169. KelpDAO’s terms of service identify Evercrest as the company that provides the Kelp app.
What KelpDAO Alleges
KelpDAO’s official account responded at 03:56:58 UTC on September 25, about five hours after Pellegrino’s post. The team said it had filed the claim “to right the wrongs associated with the exploit of rsETH’s LayerZero bridge earlier this year” and linked to a longer statement published on X.
In that statement, KelpDAO alleged that the exploit resulted from LayerZero’s failure to disclose weaknesses in its own technology and its failure to prevent an infiltration of its security infrastructure. The team said LayerZero and Pellegrino later “publicly blamed us for their failures” and claimed LayerZero had “reviewed and endorsed, in writing” KelpDAO’s deployment and configuration.
KelpDAO added that it has since moved rsETH’s bridge to “a more secure cross-chain security standard” and that the complaint “lays out the record.” None of these allegations have been tested in court. The Crypto Times has not independently verified the specific damages or other relief sought in the claim.
How the April 18 Exploit Unfolded
The dispute dates back to Saturday, April 18, 2026. At 17:35 UTC, an attacker called the lzReceive function on LayerZero’s EndpointV2 contract and drained 116,500 rsETH from KelpDAO’s Omnichain Fungible Token (OFT) adapter on Ethereum.
On-chain records place that drain in transaction 0x1ae23..b4222, from adapter 0x85d4..98ef3.
The stolen amount equaled about 18% of rsETH’s circulating supply. KelpDAO’s emergency pauser multisignature (multisig) wallet froze core contracts about 46 minutes later at 18:21 UTC and blocked two follow-up attempts at 18:26 UTC and 18:28 UTC that would have taken another 40,000 rsETH, worth roughly $100 million in contemporaneous reports by The Block; KelpDAO’s April 20 statement put the blocked second attempt at about $95 million.
Blockchain analytics firm Chainalysis described the attack as a breach of off-chain infrastructure rather than a smart contract bug. According to its analysis, attackers fed false source-chain data to infrastructure used by the LayerZero Labs Decentralized Verifier Network (DVN), the service that confirms cross-chain messages. The Ethereum-side contract then released rsETH against a token burn that never took place on the source chain. Investigators linked the operation to North Korea’s Lazarus Group, specifically the TraderTraitor cluster, also tracked as UNC4899.
LayerZero’s incident report dated May 20, 2026, said the breach began on March 6, 2026, when an attacker socially engineered a LayerZero Labs developer, harvested session keys, and gained access to the company’s remote procedure call (RPC) cloud environment. The attacker then poisoned internal RPC nodes, which are servers that relay blockchain data. A denial-of-service (DoS) attack on an external RPC provider forced the LayerZero Labs DVN onto the compromised nodes, which then approved a forged cross-chain message.
LayerZero said the attack succeeded because the affected omnichain application (OApp) relied on a single verifier, known as a 1-of-1 DVN configuration.
Months of Public Blame
LayerZero’s initial statement said the incident was isolated to KelpDAO’s rsETH configuration and that KelpDAO had used a single DVN against recommended multi-verifier practice. The Crypto Times reported that position on April 20.
KelpDAO rejected that account. The team argued that the 1-of-1 setup was LayerZero’s documented default, that LayerZero staff had reviewed its configuration, and that data from the analytics platform Dune showed about 47% of active LayerZero OApps used the same model. KelpDAO also announced plans to move to Chainlink’s Cross-Chain Interoperability Protocol (CCIP).
On May 5, at 21:50:59 UTC, Pellegrino published a detailed technical rebuttal on X. He said KelpDAO originally used multi-DVN or DeadDVN defaults before manually switching routes to 1-of-1 configurations, including a change on April 1, 2024, and later Unichain deployments. He also cited LayerZero documentation warning integrators not to treat a single DVN as production-ready. Those on-chain configuration dates and document citations are Pellegrino’s account and have not been independently re-audited for this article.
LayerZero’s tone shifted between May 8 and May 10. The company acknowledged that it had “made a mistake by allowing our DVN to act as a 1/1 DVN for high-value transactions” and said it would no longer sign single-verifier setups. It later published a technical breakdown of the flaw.
Where the Stolen Funds Went
The attacker used the stolen rsETH as collateral on lending protocols, including Aave. Arbitrum’s Security Council later froze about 30,766 ETH, worth about $71 million at the time. Those frozen funds became the subject of a separate legal dispute in New York tied to an older judgment against North Korea.
Several DeFi projects later joined a recovery effort to cover the shortfall, and Aave restored rsETH backing in full by June 1. Aave’s June 1, 2026 post-mortem, previously reported by The Crypto Times, said the LayerZero OFT adapter was refilled in five tranches totaling 116,131.72 rsETH, with the last tranche of 20,373.72 rsETH sent on May 26. That figure is slightly below the 116,500 rsETH originally drained. A separate New York fight over the frozen Arbitrum ETH was still outstanding at that date.
What Comes Next
The BC filing moves a months-long public dispute into a formal legal process. KelpDAO says it holds written approval from LayerZero for its configuration, while Pellegrino maintains that KelpDAO chose the single-verifier setup against documented guidance. How a Canadian court weighs those competing accounts could shape how cross-chain protocols and the applications built on them divide responsibility for security failures.
The Crypto Times will update this story as court documents and further statements become available.
Also Read: Hut 8 Wins $140M Bid for Poolin’s Texas Data Centers Ahead of Sept. 29 Court Hearing
