4 hours ago

LayerZero faces $292 million suit as nearly $15 billion shifts away

Nearly $15B is moving off LayerZero, now a $292M lawsuit puts its security model on trial

CryptoSlate

Evercrest Technologies sued LayerZero Labs, its Canadian affiliate, and CEO Bryan Pellegrino in British Columbia over April's $292 million rsETH exploit. The claim alleges negligent misrepresentation, negligence, and defamation. It seeks aggravated and punitive damages. Kelp users have withdrawn more than $650 million since the attack. Pellegrino called the suit meritless. Projects tied to roughly $14.5 billion in assets had announced moves from LayerZero to Chainlink's CCIP by Aug. 4. BitGo accounted for about $7.4 billion of that tally through WBTC. BitGo named CCIP its exclusive cross-chain provider for WBTC. On April 18, attackers tricked LayerZero's verifier into approving a forged cross-chain transfer. LayerZero's incident report traced the intrusion to a developer who was socially engineered into cloning a malicious GitHub repository in March. The attackers reached LayerZero's RPC environment. They poisoned two internal nodes. They knocked an external RPC provider offline. The verifier then signed a message built on false source-chain data. The attack caused 116,500 rsETH to leave Kelp's bridge. Kelp's bridge required approval from LayerZero's single verifier. LayerZero's on-chain signature check worked as designed because the signature was valid. The signature attested to false information. LayerZero's report assigned the verifier requirement to the application. The report assigned the compromised RPC layer to LayerZero as its operator. Evercrest alleges that LayerZero reviewed and approved the single-verifier setup in writing. Evercrest says LayerZero told Kelp in February 2024 that a default configuration had no problem. The suit also alleges that LayerZero warned USDT0 about risks in default verifier configurations. It alleges that LayerZero did not give Kelp a comparable warning. The allegations have not been tested in court. LayerZero says Kelp had previously used a two-of-two configuration. LayerZero says Kelp moved to a one-of-one configuration. LayerZero's verifier now refuses to sign on any channel where it is the only required signer. The company requires multiple independent RPC sources across providers and geographies. By Aug. 4, LayerZero had moved default pathways on both versions of its endpoint to a minimum of three verifiers. Applications can still build custom setups at the protocol level. LayerZero said in May that allowing its verifier to act alone on high-value transfers had been a mistake. LayerZero said the incident affected about 0.14% of applications on its network. Mantle, Kelp's rsETH, and Lombard added billions of dollars to the migration total. Chainlink put the total near $15 billion. Kelp said its own migration remained underway, so announced value and completed transfers were separate measures. Wyoming's Stable Token Commission moved its FRNT state-issued token off LayerZero in August. The commission signed a multi-year deal making CCIP its exclusive cross-chain provider. Commission CISO Keith Lawhorn said on Sept. 14 that the review began because of the Kelp attack. He said the review found problems with access controls, private key management, and incident disclosures. LayerZero has partly disputed those findings. LayerZero remains a network spanning 96 chains. DefiLlama reported $9.5 billion in bridged volume for LayerZero over the past 30 days. A court in British Columbia will decide which party owed the safeguards involved in the integration.

This content is an AI-generated summary/analysis for informational purposes only and does not constitute investment advice.