Nearly $15B Moves Off LayerZero After $292M Exploit
About $14.5 billion in assets have announced migrations off LayerZero after an April 18 rsETH exploit that stole $292 million. Evercrest sued LayerZero Labs and CEO Bryan Pellegrino in British Columbia.
Evercrest Technologies, the company behind KelpDAO, has sued LayerZero Labs, its Canadian affiliate, and CEO Bryan Pellegrino in British Columbia after an April 18 exploit that drained 116,500 rsETH, about $292 million. The complaint alleges negligent misrepresentation, negligence and defamation and seeks aggravated and punitive damages. Pellegrino called the suit “meritless.”
Evercrest says attackers in March tricked a LayerZero developer into cloning a malicious GitHub repository. That access, the complaint says, let the intruders reach LayerZero’s RPC environment, poison two internal nodes and knock an external RPC provider offline. With LayerZero’s verifier attesting to false source-chain data, funds left Kelp’s bridge. Evercrest says Kelp users have withdrawn more than $650 million since the attack.
LayerZero’s incident report described two failures aligning: the bridge’s reliance on a single verifier and the compromise of the provider-operated RPC layer that fed the verifier false data. The report states the bridge’s on-chain contract accepted a signature that was valid for the falsified message. LayerZero attributed the number of required verifiers to the application and the compromised RPC infrastructure to its operation.
Evercrest alleges LayerZero reviewed and approved the single-verifier configuration in writing, including telling Kelp in February 2024 there was “no problem” with the default setup. The complaint also says LayerZero warned another developer about default-verifier risks while withholding comparable advice from Kelp. Those claims have not been tested in court. LayerZero says Kelp previously used a two-of-two configuration and later chose a one-of-one setup.
After the exploit, LayerZero changed its operational rules. The company now refuses to sign on any channel where its verifier is the only required signer and requires multiple independent RPC sources across providers and geographies. By Aug. 4 the firm said it had raised minimum defaults on both versions of its endpoint to three verifiers while still allowing applications to configure custom setups. In May LayerZero said letting its own verifier act alone on high-value transfers had been a mistake and estimated the incident affected roughly 0.14% of applications on the network.
Market reaction preceded the litigation. By early May projects representing more than $3 billion had announced moves away from LayerZero. By July that figure passed $7 billion. By Aug. 4 projects tied to roughly $14.5 billion in assets had announced migrations to Chainlink’s Cross-Chain Interoperability Protocol, nearly 50 times the value of the rsETH theft. BitGo accounted for the largest single migration, with WBTC representing about $7.4 billion of the Aug. 4 total; BitGo named CCIP its exclusive cross-chain provider for WBTC and the default for future BitGo-issued assets. Kelp says its own migration work remains underway and that announced value does not equal completed transfers.
Some institutional users formalized changes. Wyoming’s Stable Token Commission fully migrated its state-issued FRNT token off LayerZero in August and signed a multi-year deal making CCIP its exclusive cross-chain provider. Keith Lawhorn, the commission’s CISO, said the review began because of the Kelp attack and identified problems with access controls, private key management and incident disclosures. LayerZero has disputed parts of those findings.
LayerZero’s network spans 96 chains and reported about $9.5 billion in bridged volume in the 30 days before the Aug. 4 tally, based on on-chain data. Evercrest’s suit asks the British Columbia court to decide who bore responsibility for the safeguards: the application that set its verifier requirements or the provider that operated the infrastructure the verifier depended on. The court will weigh written approvals, configuration choices and the evidence presented by both parties.








