The Lawsuit That Changes Everything
On September 25, 2026, Evercrest Technologies — the entity behind KelpDAO — filed suit against LayerZero Labs and its CEO, Bryan Pellegrino, in the Supreme Court of British Columbia. The claims are not minor: negligence, negligent misrepresentation, and defamation, all stemming from a catastrophic $292 million exploit of the rsETH bridge that occurred on April 18, 2026, and which allegedly involved compromised LayerZero infrastructure at its core (CoinDesk).
This is a rare and reputationally dangerous combination. Negligence and misrepresentation claims attack LayerZero's competence and honesty about its security posture. A defamation claim layered on top suggests the dispute has spilled into public statements, accusations, and finger-pointing between two crypto infrastructure players — the kind of mutual mudslinging that erodes trust across an entire ecosystem, not just the two companies involved. For a cross-chain messaging protocol whose entire value proposition rests on being a trusted, secure backbone for other protocols to build on, a lawsuit alleging it misrepresented its security is close to an existential threat. This is precisely the scenario where a coordinated legal-and-communications response matters — the kind of dual-track defense outlined in our crisis reputation management framework, where litigation strategy and public narrative control have to move in lockstep.
How the $292 Million Actually Disappeared
The backstory, disclosed by LayerZero itself, is arguably more damaging than the lawsuit. According to LayerZero's own incident report, a LayerZero Labs developer was socially engineered by North Korean state-sponsored threat actors — identified as the TraderTraitor/Lazarus Group — in an operation that allowed attackers to harvest session keys, pivot into LayerZero's cloud environment, and poison internal RPC nodes (LayerZero Labs KelpDAO Incident Report). That compromised infrastructure is what ultimately enabled the theft of 116,500 rsETH — roughly $292 million — from the KelpDAO bridge in April 2026, making it one of the largest crypto exploits of the year.
The details matter for reputation purposes. This wasn't a novel smart contract bug or an unavoidable zero-day; it was a social engineering breach of a single employee that cascaded into control of core infrastructure trusted by dozens of downstream protocols. For an infrastructure provider, admitting that a phishing-style attack on one developer's credentials could compromise the entire messaging layer is a devastating admission — and it's exactly the kind of finding that fuels both litigation and long-tail negative search results. Every future search for
Sources
Disclaimer: The information presented in this article was published by third parties and is aggregated here for research and commentary purposes only. NegativePublicRelations.com does not claim these allegations as fact; all claims are attributed to their original publishers, linked above. Readers are encouraged to review the original sources. This post is not legal advice.
“LayerZero Labs is facing a defamation and negligence lawsuit from KelpDAO over a $292 million bridge exploit tied to a North Korean social-engineering attack — the latest chapter in a recurring pattern of security failures and litigation dating back to FTX's 2023 lawsuit.”
How NegativePublicRelations.com would respond
placeholder
This post is based on reporting by CoinDesk. We rewrite and analyze the story; the original article remains the property of its publisher.
KelpDAO sues LayerZero and CEO over $292M rsETH bridge exploitFacing a similar situation? Our reputation strategists can help.
Explore our placeholder defense service





