LayerZero's security is under fire after a $292 million exploit. Nearly $15 billion in assets are moving to Chainlink's CCIP, and a major lawsuit is now in court.
Nearly $15 billion in crypto is on the move after a major exploit and lawsuit put LayerZero's security in question. The $292 million rsETH bridge attack in April set off a rush of projects-some of the biggest in the space-leaving LayerZero for Chainlink's CCIP. Now, a Canadian court will decide if LayerZero or its client KelpDAO is to blame for the breach.
Legal battle over bridge security
Evercrest Technologies, which runs KelpDAO, has sued LayerZero Labs, its Canadian arm, and CEO Bryan Pellegrino in British Columbia. The lawsuit claims negligent misrepresentation, negligence, and defamation. Evercrest wants aggravated and punitive damages. The company says LayerZero reviewed and approved Kelp's single-verifier bridge in writing, telling Kelp in February 2024 that the default setup was "no problem." The suit also says LayerZero warned another developer about single-verifier risks but did not give Kelp the same warning. These claims have not been tested in court. Pellegrino has called the lawsuit baseless.
The $292 million rsETH bridge exploit is the largest DeFi attack of 2026, sparking one of the most significant legal disputes over cross-chain protocol liability to date.
The fight is over who is responsible for the bridge's weakness. On April 18, attackers tricked LayerZero's verifier into approving a fake cross-chain transfer. LayerZero's incident report says the breach started when a developer was socially engineered into cloning a malicious GitHub repo. This gave attackers access to LayerZero's RPC environment. They poisoned two internal nodes and shut down an external RPC provider. The verifier then signed off on a fake message. The bridge's smart contract accepted the signature and released 116,500 rsETH from Kelp's bridge. LayerZero's report splits the blame: Kelp set up the bridge to need only one verifier-LayerZero's own-while LayerZero ran the compromised infrastructure.
Mass migration to Chainlink CCIP
By August 4, projects holding about $14.5 billion in assets had announced plans to leave LayerZero for Chainlink's CCIP. That's nearly 50 times the amount stolen in the exploit. BitGo led the way, moving $7.4 billion in WBTC and naming CCIP as its only cross-chain provider for WBTC and future BitGo assets. Mantle, Kelp's rsETH, and Lombard added billions more. Chainlink put the total near $15 billion. KelpDAO's own migration is still underway, so the full value is not yet reflected in completed transfers.
Wyoming's Stable Token Commission also moved its FRNT state token off LayerZero in August, signing a multi-year deal with Chainlink. The commission's CISO said the Kelp attack triggered a review that found problems with access controls, private key management, and incident disclosures. LayerZero has pushed back on some of these findings. The commission now requires infrastructure that is secure by default, with built-in protections for public issuers.
LayerZero's incident report attributes the exploit to a combination of social engineering, RPC infrastructure compromise, and the use of a single-verifier setup, which allowed attackers to forge a cross-chain message and withdraw 116,500 rsETH without a corresponding burn on the source chain.
Protocol changes and industry impact
LayerZero has changed its default security setup. Its verifier now refuses to sign on any channel where it is the only required signer. The company now requires multiple independent RPC sources from different providers and regions. By August 4, LayerZero had updated both versions of its endpoint to need at least three verifiers by default, though apps can still change their setups. In May, LayerZero admitted that letting its own verifier act alone on big transfers was a mistake. The company says only about 0.14% of apps on its network were affected by the incident.
The bridge exploit and the wave of migrations have forced the industry to look hard at who is responsible for cross-chain infrastructure. KelpDAO chose how many verifiers its bridge needed. LayerZero ran the infrastructure those verifiers used. Both sides failed, and the smart contract did what both allowed. This setup is common when protocols rely on a single company for oracles, custody, or sequencing. Smart contracts treat whatever those services say as final. LayerZero now works across 96 chains and reported $9.5 billion in bridged volume over the past 30 days, according to DefiLlama.
This migration is much bigger than past incidents. In another case, reported earlier, a five-day network halt led to trading restrictions but did not cause a similar asset flight. The LayerZero-KelpDAO dispute now puts the question of cross-chain security and provider liability in front of the courts.
Data shows more than $650 million was withdrawn by Kelp users after the April exploit. The $292 million loss from the rsETH bridge attack is one of the biggest single bridge exploits so far. By August 4, the value of assets announced for migration from LayerZero to Chainlink's CCIP reached about $14.5 billion, with BitGo's WBTC making up $7.4 billion of that. LayerZero's network is still moving large amounts, with $9.5 billion in bridged assets over the past 30 days, based on DefiLlama numbers.
The LayerZero case shows how risky it is when cross-chain bridges and interoperability protocols depend on a single verifier or provider. If that layer is compromised, users and projects can lose everything. The lawsuit between Evercrest and LayerZero will test how much responsibility infrastructure providers have when clients pick risky setups but the provider runs the key systems. As the industry moves to stronger multi-verifier and multi-provider setups, the outcome of this case could decide how future bridge security rules are set and who gets the blame when things go wrong.