Crypto news report · source clearly identified

Nearly $15 B Shifts Away from LayerZero as $292 M Lawsuit Challenges Its Security Model

Evercrest Technologies, the company behind KelpDAO, has sued LayerZero Labs and its CEO over a $292 million rsETH exploit, while projects controlling roughly $14.5 billion have announced moves to Chainlink’s CCIP.

Evercrest Technologies, the operator of KelpDAO, filed a lawsuit in British Columbia against LayerZero Labs, its Canadian affiliate, and CEO Bryan Pellegrino. The claim stems from the April rsETH exploit that resulted in a loss of $292 million.

Key allegations

  • Negligent misrepresentation and negligence by LayerZero regarding verifier configuration.
  • Defamation claims.
  • Requests for aggravated and punitive damages.
  • Reference to over $650 million withdrawn by Kelp users since the attack.

Technical background of the exploit

On April 18, attackers deceived LayerZero’s verifier into approving a forged cross‑chain transfer. The breach involved a developer being socially engineered to clone a malicious GitHub repository, leading to poisoning of LayerZero’s RPC environment and the signing of a message based on false source‑chain data. The compromised verifier authorized the release of 116,500 rsETH from Kelp’s bridge.

Responsibility split

LayerZero’s incident report assigns responsibility to two layers:

  • Application layer (Kelp): Chose a single‑verifier setup, deviating from a previously used two‑of‑two configuration.
  • Infrastructure layer (LayerZero): Operated the RPC nodes that were poisoned, allowing the verifier to sign false data.

Migration wave

By August 4, projects controlling roughly $14.5 billion announced migrations from LayerZero to Chainlink’s Cross‑Chain Interoperability Protocol (CCIP). Notable moves include:

  • BitGo shifting about $7.4 billion of WBTC to CCIP.
  • Wyoming’s Stable Token Commission moving its FRNT token to CCIP.
  • Other assets such as Mantle, Lombard and Kelp’s rsETH contributing to the total.

Implications for cross‑chain security

The lawsuit highlights a broader question about who bears responsibility when a configurable security component fails. If courts find that LayerZero’s written approval of Kelp’s single‑verifier design creates liability, providers may need to offer warranties, indemnities, or enforce stricter default safeguards.

Current status

LayerZero maintains that the suit is meritless and has updated its protocol to require a minimum of three independent verifiers for new deployments. The case will determine how responsibility is allocated between application developers and infrastructure providers in the DeFi ecosystem.

Source & attribution

News Source

Publisher
CryptoSlate
Original date
September 26, 2026, 1:30 PM
Original headline
Nearly $15B is moving off LayerZero, now a $292M lawsuit puts its security model on trial
View original report ↗