The dispute centers on the April 18 incident, which saw attackers siphon roughly $292 million after compromising LayerZero’s own infrastructure. Evercrest Technologies Inc., the entity behind Kelp, alleges that LayerZero failed to disclose critical technology risks and neglected to secure the infrastructure used by its verifiers. According to the complaint, LayerZero had reviewed and approved the bridge’s deployment in writing, contradicting the company’s later claims that Kelp’s specific configuration created a singular, avoidable point of failure.
LayerZero and Pellegrino have dismissed the allegations as meritless, with the co-founder vowing to defend the case in Vancouver. In its technical post-mortem, LayerZero argued that the breach was facilitated by Kelp’s use of a 1-of-1 Decentralized Verifier Network (DVN). The company maintains that had Kelp implemented a multi-verifier setup, the forged cross-chain messages would have been rejected. Forensic findings from Chainalysis and Blockaid confirmed that attackers manipulated LayerZero-operated RPC nodes to feed false data to the verifier, effectively bypassing security protocols. Since the attack, Kelp has migrated its cross-chain transfers to Chainlink’s CCIP, moving away from LayerZero’s framework while navigating the ongoing fallout of the theft.

Comments (0)
No comments yet. Be the first!