KelpDAO has sued LayerZero in the Supreme Court of British Columbia over the April exploit that drained 116,500 rsETH, worth about $292 million, from its bridge. The claim, filed on Friday by Evercrest Technologies, the company behind KelpDAO, names LayerZero Labs, its Canadian subsidiary and co-founder Bryan Pellegrino, and alleges negligent misrepresentation, negligence and defamation.
At the centre of the case is a configuration choice. KelpDAO’s bridge relied on a single decentralised verifier network, a so-called 1-of-1 setup, to confirm cross-chain messages. According to The Block, the claim says LayerZero told KelpDAO in writing in February 2024 that there was no problem with the default arrangement, pointed it the following month to the same configuration used by another bridge, and warned a different developer, USDT0, about similar risks without telling KelpDAO. The attack has been attributed to a North Korean group that reached LayerZero’s infrastructure through social engineering and malware on a developer’s computer.
The fallout went well beyond one protocol. CoinDesk reports that around $20 billion of DeFi deposits were pulled in the aftermath, with Aave borrowing $300 million to meet withdrawals, and KelpDAO cites more than $650 million in withdrawals from its own platform. It also says LayerZero publicly blamed it for failures that were LayerZero’s own, which underpins the defamation count.
Pellegrino said the claim continues to be meritless and that he would meet KelpDAO in Vancouver. The public accounts of the filing do not include a damages figure. The more lasting question is one DeFi has long avoided answering: when an infrastructure provider publishes defaults and advises on settings, does it share responsibility when those settings fail, or does every protocol own its configuration alone?



