$292M Lawsuit Tests Bridge Vendor Liability for DeFi Code Endorsements
Evercrest's BC Supreme Court claim against LayerZero and its CEO puts bridge vendor liability, negligent misrepresentation, and personal executive liability on trial. The case will probe whether written code endorsements and social media posts create actionable duties.
Beat this week
Last 7 days · Corporate Law
Impact 6.2/10 (-0.5 vs prior). Counts are stories in our record, not a market forecast.
Open the change reportCoverage balance Negative coverage leads. Negative coverage exceeds positive coverage by 20 percentage points.
This story sits in Corporate Law — the counts compare this beat's last 7 days with the previous 7 in our verified record, not a market forecast.
Figures are computed live from our source-verified story record (as of ) The volume change compares this window with the prior 7 days in the same record. — see our methodology for how impact and sentiment are derived.
Legal briefing
Key takeaways
- Evercrest's BC Supreme Court claim against LayerZero and its CEO puts bridge vendor liability, negligent misrepresentation, and personal executive liability on trial.
- The case will probe whether written code endorsements and social media posts create actionable duties.
In this briefing
Mentioned
Key Intelligence
Key Facts
- 1Evercrest Technologies filed a notice of civil claim in the Supreme Court of British Columbia on September 23, 2026, seeking aggravated and punitive damages over the $292 million rsETH bridge exploit.
- 2The claim alleges LayerZero called Evercrest's draft code "good" in February 2024 and directed the 1-of-1 verifier setup with its own verifier in March 2024.
- 3Evercrest says LayerZero warned USDT0 about default verifier configuration risks in late 2024 or early 2025 but did not give KelpDAO a comparable warning.
- 4The exploit allegedly began on March 6, 2025, with malware on a LayerZero developer's computer that enabled node tampering and false verifier readings.
- 5On April 18, 2025, the attacker disabled third-party nodes, causing 116,500 unbacked rsETH to be minted on Unichain and draining $292 million.
- 6Bryan Pellegrino, LayerZero co-founder and CEO, is sued personally over Telegram and X posts and has dismissed the lawsuit as meritless.
Who's Affected
Analysis
For legal and regtech professionals, this is a test of how courts allocate liability for smart-contract security failures when an infrastructure vendor allegedly specified the exact configuration later exploited. The claim pleads negligent misrepresentation, negligence, and defamation, including personal posts by CEO Bryan Pellegrino, and seeks aggravated and punitive damages. Discovery and rulings will shape vendor due diligence standards, executive communications risk, and cross-border DeFi litigation tactics.
Evercrest Technologies, the developer behind restaking protocol KelpDAO, has filed a notice of civil claim in the Supreme Court of British Columbia against LayerZero Labs Ltd., LayerZero Labs Canada Inc., and LayerZero co-founder and CEO Bryan Pellegrino. The claim, filed on September 23, 2026, alleges that LayerZero endorsed in writing the exact bridge configuration it later blamed for the April 2025 exploit that drained $292 million from the protocol. The causes of action include negligent misrepresentation, negligence, and defamation, with Evercrest seeking aggravated and punitive damages over both the financial loss and Pellegrino's subsequent public statements.
For markets and token holders, the $292 million exploit raises questions about rsETH collateral and the resilience of restaking protocols.
The legal dispute centers on a 1-of-1 verifier architecture. Evercrest contends that its KelpDAO bridges ran with LayerZero's own verifier network as the sole party confirming that tokens had been locked on one chain before equivalent tokens were minted on another. According to the filing, LayerZero told Evercrest in February 2024 that its draft code was "good" and that there was "[n]o problem" using the default configuration. In March 2024, LayerZero allegedly directed Evercrest to use a 1-of-1 setup with LayerZero's own verifier. Then, in January 2025, LayerZero said that even if a verifier were compromised, the most it could do was fail to verify a message correctly. The claim states that LayerZero warned a separate developer, USDT0, about risks in its default verifier configurations in late 2024 or early 2025, prompting USDT0 to run its own verifier. Evercrest says it received no comparable warning.
The attack chain described in the claim began inside LayerZero's own environment. An attacker allegedly placed malware on a LayerZero developer's computer on March 6, 2025, then tampered with LayerZero's nodes so they fed false readings to the verifier. On April 18, 2025, the attacker disabled the third-party nodes the verifier also used, so the verifier was told 116,500 rsETH had been locked on Unichain when nothing had been locked. Because only one verifier was required, the tokens were minted without backing, resulting in the $292 million loss. Evercrest says it paused the bridges within about an hour and blocked a second attempt, limiting further damage.
LayerZero and Pellegrino have pushed back. Cointelegraph reports that Pellegrino dismissed the lawsuit as meritless, though the sources do not provide a detailed legal response. The personal naming of Pellegrino is notable because the suit alleges defamation over his posts on Telegram and X, meaning his individual communications after the exploit could become evidence. The claim seeks aggravated and punitive damages, which require proof of conduct beyond ordinary negligence and could amplify the case's stakes.
The broader implications matter for the entire cross-chain interoperability sector. Bridges remain a critical vulnerability in decentralized finance because they concentrate trust in a small set of verifiers, oracles, or multisig signers. A 1-of-1 configuration removes redundancy and creates a single point of failure; if that point is compromised, unbacked assets can be minted. The lawsuit argues that LayerZero, as the vendor providing that architecture and the entity whose systems were compromised, bears responsibility. If Evercrest prevails, infrastructure providers may face a duty to warn clients when default configurations carry material security risks, and written assurances about code quality could create actionable representations. The fact that LayerZero allegedly warned USDT0 but not KelpDAO could support a differential treatment argument.
What to Watch
For markets and token holders, the $292 million exploit raises questions about rsETH collateral and the resilience of restaking protocols. KelpDAO's pause within one hour and its successful block of a second attempt suggest operational responsiveness, but the underlying trust assumption was still broken. The case also highlights governance and vendor concentration risk: many DeFi protocols rely on a small number of interoperability layers, which in turn rely on internal security practices and employee endpoint hygiene.
Looking forward, the litigation could establish precedent for how courts treat smart-contract infrastructure providers and their executives. Discovery may reveal internal communications about risk warnings, code reviews, and post-incident public statements. The outcome could push the industry toward decentralized verifier networks, mandatory redundancy, and clearer liability disclaimers. It could also make executives more cautious about public commentary after security incidents, since defamation and punitive damage claims can attach to social media posts. The case will be watched by DeFi developers, security researchers, and legal teams across jurisdictions as a benchmark for vendor accountability in the blockchain economy.
Timeline
Timeline
LayerZero allegedly approves draft code
LayerZero tells KelpDAO's developer that its draft code is "good" and there is "[n]o problem" using the default configuration.
1-of-1 verifier setup directed
LayerZero allegedly instructs Evercrest to use a 1-of-1 setup with LayerZero's own verifier.
LayerZero risk statement
LayerZero says a compromised verifier could at most fail to verify a message correctly.
Malware installed on developer machine
An attacker places malware on a LayerZero developer's computer and begins tampering with LayerZero nodes.
Bridge exploit drains $292M
Attacker disables third-party nodes, causing the verifier to confirm 116,500 rsETH locked on Unichain when none were; tokens are minted unbacked. KelpDAO pauses bridges within about an hour.
Civil claim filed
Evercrest Technologies files a notice of civil claim in the Supreme Court of British Columbia against LayerZero and Bryan Pellegrino.
Cite This Page
"$292M Lawsuit Tests Bridge Vendor Liability for DeFi Code Endorsements." Legal & RegTech Intelligence Brief, September 25, 2026. https://getlegalbrief.com/story/kelpdao-layerzero-legal-vendor-liability
How we covered this story
Every story in our legal coverage is assembled from multiple primary sources, cross-referenced for factual consistency, and scored along three independent dimensions: sentiment, operational impact, and source-cluster confidence. Single-source rumors and unverifiable claims do not pass our editorial gate. When a story shows "Verified by N sources" with N≥2, the development is independently corroborated; when N=1, we mark it explicitly so readers can weigh the signal accordingly.
Impact scoring uses a 1-10 scale weighted toward regulatory, financial, and operational consequence rather than coverage volume. A topic that runs in every outlet but moves no real decisions ranks lower than a niche regulatory filing that reshapes how operators in the legal space have to behave. Read our full methodology for the scoring rubric, our glossary for term definitions, and our trends index for the longitudinal view across the beat.
Sources are only linked to a story once they clear our classification pipeline at a minimum 35 percent relevance threshold. According to that methodology, reviewed July 2026, this follows multi-source corroboration standards recommended by journalism research bodies such as the Reuters Institute for the Study of Journalism.
See something wrong in this story — a wrong fact, a broken source link, a misattributed entity? Report a data issue.
| Signal on this page | What it tells you |
|---|---|
| Verified by N sources | Independent corroboration count. N≥2 is our confidence floor; N=1 is marked explicitly. |
| Impact score (1-10) | Regulatory + financial + operational weight. 8+ signals an experienced-operator action item. |
| Sentiment | Five-tier classification trained on labeled legal-specific corpora. |
| Timeline | Where applicable, the related-events sequence that contextualizes today's development. |