$292M Bridge Theft Escalates Into Legal Battle

A cryptocurrency theft involving nearly $300 million is evolving from a technical security incident into a fierce legal dispute. According to public court filings, Evercrest Technologies, the entity behind KelpDAO, has recently filed a lawsuit at the Supreme Court of British Columbia, Canada. The defendants include two LayerZero entities and its co-founder, Bryan Pellegrino.

The Core Dispute: A Security Assurance Turned Blame Game

The case stems from a major security breach on April 18, where attackers exploited a vulnerability to steal 116,500 rsETH, valued at approximately $292 million at the time. While the theft itself shook the industry, the lawsuit reveals a more complex controversy over accountability.

A central allegation in the complaint is negligent misrepresentation. KelpDAO claims that before deploying their cross-chain bridge service, they sought written confirmation from LayerZero regarding a critical security configuration—the default "1-of-1 DVN" (Data Availability Node) setup. LayerZero reportedly responded that this configuration was "not a problem" and failed to warn about the inherent centralization risks.

From Partnership to Accusation: The Pivotal Fallout

The relationship took a dramatic turn after the theft. The lawsuit states that instead of acknowledging its role in endorsing the security setup, LayerZero and its representatives publicly shifted blame onto KelpDAO's own management and configuration choices. KelpDAO alleges this post-incident deflection and public accusation constitute defamation, harming its business reputation.

In response, LayerZero's Bryan Pellegrino has publicly stated that the claims in the lawsuit are "baseless." This sets the stage for what is likely to be a protracted, evidence-intensive legal proceeding.

Beyond the Case: Questioning Industry Security and Accountability Standards

  • The Liability of Infrastructure Providers: What legal and ethical responsibility does a protocol bear when it gives a "no problem" assurance on security configurations that a project relies upon?
  • Post-Incident Communication and Crisis Management: Should parties collaborate on investigations after a security breach, or rush to assign blame? This lawsuit highlights a lack of industry standards for crisis response and shared responsibility.
  • Transparency and Informed Consent on Technical Configs: Whether the risks of configurations like "1-of-1," which introduce single points of failure, were fully and clearly disclosed could become a key focus of the trial.

Regardless of the final verdict, this case serves as a stark warning for the broader Web3 ecosystem. It goes beyond the loss of funds, probing a critical question: how should legal liability be apportioned among different protocol layers and entities when failures occur in complex tech stacks? The outcome may set a new precedent for future partnership agreements and security audit practices.