LayerZero Sued Over rsETH Exploit as Dispute Over Blame Escalates
تابع على أخبار Google أضف كمصدر مفضل في أبرز أخبار Google

LayerZero Sued Over rsETH Exploit as Dispute Over Blame Escalates

رؤى رئيسية:

  • KelpDAO’s parent sues LayerZero over the rsETH bridge exploit valued at $292 million.
  • Evercrest alleges LayerZero endorsed the bridge’s disputed 1-of-1 DVN configuration.
  • Evercrest reports over $650M in withdrawals; Pellegrino calls the claim meritless.

LayerZero faces a lawsuit from KelpDAO’s parent company over the April 18 rsETH bridge exploit, escalating their dispute over responsibility. Evercrest Technologies alleges security failures enabled attackers to steal 116,500 rsETH, worth approximately $292 million at the time.

The company also challenges later public statements blaming KelpDAO’s bridge configuration, while co-founder Bryan Pellegrino disputes the allegations.

Evercrest filed its notice of civil claim on Thursday in the Supreme Court of British Columbia. The defendants include LayerZero Labs Ltd., LayerZero Labs Canada Inc., and Pellegrino.

Evercrest alleges negligent misrepresentation, negligence, and defamation, seeking damages that include aggravated and punitive damages.

LayerZero Lawsuit Challenges Bridge Security Assurances

ال complaint centers on the Unichain bridge’s 1-of-1 decentralized verifier network, or DVN, configuration.

Evercrest alleges the technology provider reviewed and endorsed that setup in writing before the exploit. Its account challenges later statements that KelpDAO’s configuration contradicted the provider’s recommended multi-DVN model.

According to the filing, written communications dated February 2, 2024, stated there was “no problem” using the default DVN configuration.

LayerZero faces a KelpDAO lawsuit over rsETH bridge exploit | Source: X
LayerZero faces a KelpDAO lawsuit over rsETH bridge exploit | Source: X

Evercrest further alleges that instructions on March 21, 2024, directed it toward another bridge’s identical 1-of-1 setup. The company cites both exchanges to support its allegations concerning the advice it received.

The filing also describes assurances about redundancy across multiple locations, monitoring systems, and alerts within the provider’s DVN infrastructure.

Evercrest says those representations contributed to its awareness of the system’s security. It alleges the provider described a compromised DVN’s maximum capability as failing to verify a message correctly.

Evercrest contrasts those assurances with warnings allegedly shared with USDT0 before the attack. According to the complaint, the developer received warnings about risks associated with default DVN configurations.

Evercrest says it received neither equivalent warnings about the single-verifier arrangement nor advice to adopt multiple DVNs.

Exploit Account Places Security Infrastructure in Dispute

The claim places the attack at approximately 17:35 UTC on April 18. Evercrest alleges attackers accessed the provider’s security infrastructure after social engineering led to malware installation on a developer’s computer. It attributes the resulting exploit to that intrusion and alleged weaknesses within the provider’s technology.

In addition, Evercrest argues that the provider failed to disclose those weaknesses and prevent the infiltration. The company claims that its own systems did not cause the exploit.

These allegations strengthen its effort to assign responsibility for the stolen rsETH and subsequent harm described in its complaint.

The dispute also covers statements made after the attack. Evercrest says Pellegrino publicly blamed KelpDAO for adopting the 1-of-1 configuration, despite the earlier written endorsements it describes.

Its defamation claim challenges that public account alongside the allegations concerning technical safeguards and prior communications.

Withdrawals and Product Changes Follow the Attack

Beyond the stolen tokens, Evercrest says KelpDAO users withdrew more than $650 million in assets following the exploit. The company also alleges the incident disrupted its stablecoin plans.

Its sbUSD product was shut down afterward, adding another consequence described in the filing. Meanwhile, Evercrest says it has begun migrating rsETH’s bridge to an alternative cross-chain security standard.

Its public statement describes the migration as part of efforts to protect users’ assets. The company says its lawsuit also seeks accountability for the harm outlined in its complaint.

Pellegrino rejected the allegations in a response on X. “The claim continues to be meritless,” he said. He added that he would defend himself accordingly.

نشر مقال LayerZero Sued Over rsETH Exploit as Dispute Over Blame Escalates أولاً على ذا كوين ريبابليك.

هذه ليست نصيحة استثمارية التحليل المنشور هنا هو لأغراض المعلومات فقط. الأصول الرقمية متقلبة وقد تخسر كامل قيمة استثمارك. قم بإجراء بحثك الخاص قبل اتخاذ أي إجراء.
روبام روي

روبام روي

أنا شغوف بأسواق المال ولدي خبرة 4 سنوات، متخصص في العملات الرقمية والقطاع المالي الأوسع. خريج تخصص اللغة الإنجليزية، أجمع بين شغفي الصحفي واهتمامي العميق بالبلوكشين، الأصول الرقمية، واتجاهات التكنولوجيا المالية. بالإضافة إلى التغطية والتحرير، أحب الكتابة وتأليف الأغاني.