LayerZero Hit With $292M Lawsuit as Nearly $15B in Projects Shift to Chainlink CCIP

AI Market Summary
A $292M lawsuit tied to the rsETH bridge exploit escalates headline and counterparty risk around LayerZero, reinforcing concerns over verifier/RPC security and disclosure practices. Concurrently, projects representing roughly $15B in assets have announced migrations from LayerZero to Chainlink's CCIP, including BitGo naming CCIP the exclusive crosschain provider for WBTC. The combined legal overhang and flow shift is supportive for LINK via CCIP adoption.
Impact level
● High
Affected assets
LINK/USDT+3.76%
AI Insight · LINK/USDTAI Insight
▼ Bearish
Trade now
⚠️ AI-generated insights are based on news content and are provided for informational purposes only. They do not constitute investment advice or represent the views of BingX. Investing involves risk. Please trade responsibly.
Evercrest Technologies has filed suit in British Columbia against LayerZero Labs, its Canadian affiliate and CEO Bryan Pellegrino, stemming from April's $292 million rsETH bridge exploit. The complaint alleges negligent misrepresentation, negligence and defamation, and seeks aggravated and punitive damages. Since the incident, users of Kelp have withdrawn more than $650 million, according to the report. Pellegrino publicly dismissed the lawsuit as meritless. The legal action lands as projects representing about $14.5 billion in assets said they would migrate from LayerZero to Chainlink's Cross-Chain Interoperability Protocol (CCIP) as of Aug. 4. BitGo made up roughly $7.4 billion of that figure through WBTC and has named CCIP its exclusive crosschain provider for WBTC. LayerZero's incident report says that on April 18 attackers induced its verifier to approve a forged crosschain transfer. The company traced the breach to March, when a developer was socially engineered into cloning a malicious GitHub repository. From there, the attackers accessed LayerZero's RPC environment, poisoned two internal nodes and knocked an external RPC provider offline. With source-chain data corrupted, the verifier signed a message built on false information. The exploit led to 116,500 rsETH leaving Kelp's bridge. The bridge design required approval from LayerZero's single verifier. LayerZero said its onchain signature verification functioned as intended because the signature itself was valid, even though it attested to inaccurate underlying data. In its post-mortem, LayerZero said the single-verifier requirement was an application-level choice, while responsibility for the compromised RPC layer sat with LayerZero as operator. Evercrest disputes that framing, alleging LayerZero reviewed and approved the single-verifier setup in writing and told Kelp in February 2024 that the default configuration posed no issue. The suit also claims LayerZero warned USDT0 about risks tied to default verifier configurations but did not provide Kelp with a comparable warning. These allegations have not been tested in court. LayerZero says Kelp previously used a two-of-two configuration and later moved to a one-of-one setup. The company has since changed its verifier policy: it will not sign on any channel where it is the only required signer, and it now requires multiple independent RPC sources across providers and geographies. By Aug. 4, LayerZero said it had moved default pathways on both versions of its endpoint to a minimum of three verifiers, though applications can still implement custom configurations at the protocol level. In May, LayerZero said allowing its verifier to act alone on high-value transfers had been a mistake, and estimated the incident impacted about 0.14% of applications on its network. The migration totals were boosted by moves involving Mantle, Kelp's rsETH and Lombard, with Chainlink placing announced migrations near $15 billion. Kelp said its own migration was still in progress, meaning announced amounts and completed transfers should be viewed separately. Separately, Wyoming's Stable Token Commission moved its state-issued FRNT token off LayerZero in August and signed a multiyear agreement naming CCIP as its exclusive crosschain provider. Commission CISO Keith Lawhorn said on Sept. 14 the review was prompted by the Kelp attack and identified issues in access controls, private-key management and incident disclosures. LayerZero has partially disputed those findings. LayerZero continues to operate across 96 chains. DefiLlama reported $9.5 billion in bridged volume through LayerZero over the past 30 days. The British Columbia court will ultimately weigh which party owed the safeguards tied to the integration.