LayerZero Faces Lawsuit Over rsETH Exploit Amid Blame Disputes

LayerZero Faces Lawsuit Over rsETH Exploit Amid Blame Disputes

Key Insights:

  • KelpDAO’s parent sues LayerZero over the rsETH bridge exploit valued at $292 million.
  • Evercrest alleges LayerZero endorsed the bridge’s disputed 1-of-1 DVN configuration.
  • Evercrest reports over $650M in withdrawals; Pellegrino calls the claim meritless.

LayerZero faces legal action from KelpDAO’s parent organization regarding the April 18 rsETH bridge incident, deepening their disagreement over accountability. Evercrest Technologies contends that security vulnerabilities allowed malicious actors to make off with 116,500 rsETH, valued at roughly $292 million at the time.

The firm additionally disputes subsequent public remarks pointing the finger at KelpDAO’s bridge configuration, whereas co-founder Bryan Pellegrino rejects these accusations.

On Thursday, Evercrest submitted its notice of civil claim to the Supreme Court of British Columbia, naming LayerZero Labs Ltd., LayerZero Labs Canada Inc., and Pellegrino as defendants.

The lawsuit puts forward claims of negligence, negligent misrepresentation, and defamation, while asking for financial remedies including punitive and aggravated damages.

LayerZero Lawsuit Challenges Bridge Security Assurances

At the heart of the complaint is the 1-of-1 decentralized verifier network, or DVN, configuration used on the Unichain bridge.

Evercrest asserts that the technology developer reviewed and provided a written endorsement of that setup ahead of the exploit. This stance contradicts later assertions maintaining that KelpDAO’s setup ran counter to the provider’s recommended multi-DVN framework.

According to documentation referenced in the filing, written correspondence from February 2, 2024, indicated that utilizing the default DVN setup presented “no problem.”

LayerZero faces a KelpDAO lawsuit over rsETH bridge exploit | Source: X
LayerZero faces a KelpDAO lawsuit over rsETH bridge exploit | Source: X

Furthermore, Evercrest claims that instructions issued on March 21, 2024, pointed them toward an identical 1-of-1 setup on a separate bridge. The corporation points to these two exchanges to substantiate claims about the guidance it received.

The court document also outlines guarantees concerning multi-site redundancy, monitoring tools, and alerts built into the provider’s DVN architecture.

Evercrest maintains these assurances shaped its understanding of system safety, noting that the provider characterized a compromised DVN’s worst-case failure merely as an inability to correctly verify a message.

Evercrest contrasts these comforting guarantees with cautions reportedly given to USDT0 prior to the hack. The complaint states that the developer was warned about potential dangers tied to default DVN configurations.

By contrast, Evercrest states it was never given equivalent cautions regarding the single-verifier setup, nor was it advised to transition to multiple DVNs.

Exploit Account Places Security Infrastructure in Dispute

The legal claim pins the timing of the breach at roughly 17:35 UTC on April 18. Evercrest states that the attackers gained entry to the provider’s security apparatus after a social engineering scheme resulted in malware being downloaded onto a developer’s workstation, linking the subsequent exploit to that intrusion alongside purported vulnerabilities in the provider’s systems.

Additionally, Evercrest argues the provider neglected to report these flaws or block the breach, insisting that its own systems were not responsible for the exploit occurring.

These arguments reinforce the company’s objective to pin responsibility for the missing rsETH and subsequent damages on the defendants.

The contention extends to remarks issued after the security breach. Evercrest points out that Pellegrino publicly blamed KelpDAO for implementing the 1-of-1 layout, despite the earlier written approvals outlined in the suit.

Its defamation grievance targets that public narrative, running parallel to issues raised over technical safeguards and prior communications.

Withdrawals and Product Changes Follow the Attack

Aside from the digital assets stolen, Evercrest reports that KelpDAO clients pulled upward of $650 million out of the platform in the wake of the breach. The organization also notes that the event derailed its stablecoin initiatives.

Operations for its sbUSD offering were halted in the aftermath, serving as another ramification detailed in the court papers. In the meantime, Evercrest mentions it has started migrating the rsETH bridge over to a different exchange assets and data.">cross-chain security standard.

A public statement from the firm frames this migration as a measure to safeguard user funds, while noting that the legal action aims to secure responsibility for the losses detailed in the filing.

Pellegrino dismissed the accusations through a post on X, stating, “The claim continues to be meritless,” and adding that he intends to mount a proper defense.

FAQ

Who filed the lawsuit against LayerZero?

Evercrest Technologies, the parent company of KelpDAO, filed the notice of civil claim.

How much was stolen in the rsETH bridge exploit?

The attackers stole 116,500 rsETH, which was valued at approximately $292 million at the time.

Where was the lawsuit filed?

The legal claim was filed in the Supreme Court of British Columbia.

What was LayerZero’s response to the allegations?

Co-founder Bryan Pellegrino dismissed the claims on X, calling the lawsuit meritless and stating he would defend himself accordingly.

This is not investment advice Analysis published here is for information only. Digital assets are volatile and you can lose the full value of your position. Do your own research before acting.

Rupam Roy

Leave a Reply

Your email address will not be published. Required fields are marked *