A developer connected to KelpDAO has filed a lawsuit against interoperability protocol LayerZero, alleging the firm approved a risky bridge configuration that ultimately enabled a $292 million exploit — and then failed to disclose known dangers to those relying on its guidance.
The Allegations
Evercrest, the developer bringing the suit, contends that LayerZero signed off on a single-verifier setup in writing on multiple occasions. According to the complaint, that configuration was presented as acceptable, giving builders confidence to proceed with an architecture that later proved catastrophic.
The core of the dispute centers on trust and communication. Evercrest claims it relied on LayerZero's repeated written approvals when structuring its bridge, only to discover that the arrangement left a single point of failure that attackers could exploit.
A written green light became the foundation of a nine-figure disaster, the lawsuit alleges.
A Double Standard?
Perhaps the most damaging claim in the filing is that LayerZero warned a different developer about the very same single-verifier risk it had approved for Evercrest. If proven, that inconsistency could suggest the firm was aware of the vulnerability while continuing to endorse the setup elsewhere.
The lawsuit frames this as a failure of duty — that LayerZero possessed knowledge of the danger but did not extend the same cautionary guidance uniformly across the developers building on its infrastructure.
The $292 million exploit underscores the ongoing security challenges facing cross-chain bridges, which have repeatedly been targeted as some of the most lucrative attack surfaces in the crypto ecosystem.
What's at Stake
The case raises broader questions about accountability when infrastructure providers offer configuration advice to the projects that build atop their protocols. Key issues likely to surface include:
- Whether written approvals create legal liability for bridge providers
- How security warnings should be distributed across an ecosystem
- The responsibility protocols bear for known vulnerabilities
For the wider industry, the outcome could influence how interoperability firms document their guidance and manage risk disclosures going forward. As bridge exploits continue to drain hundreds of millions from the sector, the legal questions around who bears responsibility remain far from settled.
