Evercrest, a prominent developer for KelpDAO, has filed a lawsuit against LayerZero over a $292 million bridge exploit, alleging that the interoperability protocol provided written approval for a vulnerable single-verifier configuration. The legal action centers on the claim that LayerZero repeatedly signed off on the security of the setup used by KelpDAO, only to later warn a different development team about the exact same risks without notifying Evercrest. This discrepancy, Evercrest argues, constitutes a breach of duty that directly led to the massive loss of liquid restaking assets in early 2026.
The exploit targeted the communication layer between KelpDAO and LayerZero’s infrastructure, where a single-verifier bottleneck allowed attackers to bypass traditional security checks. Evercrest’s filing includes alleged internal communications showing that LayerZero staff had identified the single-verifier model as a critical failure point months before the hack. Despite this internal knowledge, Evercrest maintains they were given formal assurances that their implementation met all safety standards, leading them to deploy the bridge in a state that was ultimately indefensible.
This case arrives at a pivotal moment for US crypto regulation, as the 2026 Digital Asset Oversight Act begins to clarify the 'duty of care' required by infrastructure providers. If the court finds LayerZero liable, it could establish a legal requirement for cross-chain protocols to provide equal and transparent risk disclosures to all integrating parties. The case is being closely watched by the DeFi community, as it addresses the growing tension between decentralized 'permissionless' building and the professional liabilities of protocol creators who offer integration support.
For the broader market, the $292 million loss has triggered a significant liquidity crunch for KelpDAO participants and led to a temporary de-pegging of related liquid restaking tokens (LRTs). Investors should monitor the upcoming discovery phase, which may reveal further internal logs from LayerZero regarding their auditing processes. The outcome of this trial will likely dictate how security audits and 'official approvals' are handled by cross-chain service providers moving forward, potentially increasing the cost and complexity of future DeFi integrations.