# Bridge Related Articles

HTX News Center provides the latest articles and in-depth analysis on "Bridge", covering market trends, project updates, tech developments, and regulatory policies in the crypto industry.

$7.8 Billion in Theft and Losses Reveals the Truth: Security Costs Have Become an Unavoidable Liquidity Tax for DeFi

"7.8 Billion in Thefts Reveals the Truth: Security Costs Have Become DeFi's Unavoidable 'Liquidity Tax'" A summary of Q2 2026 data reveals that security risks are now a fundamental capital cost in DeFi, directly impacting user returns and liquidity decisions. DeFiLlama recorded 88 hacking incidents with quantified losses totaling $780.3 million in Q2. April was the worst month with $644.8 million lost. DeFi protocol attacks accounted for $735.8 million, while cross-chain bridge exploits resulted in $354.4 million in losses (note: some event categorizations overlap). Cumulatively, DeFi hacks have reached $7.85 billion, with bridge losses at $3.26 billion. The quarter highlighted two primary risk categories: high-value infrastructure vulnerabilities (e.g., bridges, oracles, admin keys) causing massive single losses, and more frequent contract logic bugs. This signals a critical market shift: from post-incident analysis to preemptive pricing of risk. Users and liquidity providers now implicitly factor in the security of the entire asset pathway—not just pool APY—into their decisions. This hidden "risk premium" manifests through wider spreads, higher liquidity incentives, and capital migration towards perceived safer routes. Cross-chain bridge risks, responsible for over $353 million in Q2 losses, exemplify this change. Asset routing credibility is now part of the transaction. Following incidents like KelpDAO and THORChain, markets are demanding safer bridges, asset insurance, and clearer risk disclosure, increasing the cost of capital for riskier pathways. Consequently, security spending is transforming from a defensive cost into a core distribution cost for attracting liquidity. Protocols must invest more in audits, bug bounties, real-time monitoring, and insurance to remain competitive. Users are increasingly demanding transparency about fund flow paths, associated risks, and contingency plans. The key indicators for the industry's direction will be whether capital continues consolidating in trusted channels, if projects delay launches for enhanced audits, if insurance premiums rise, and if aggregators start displaying security risk metrics. Q2 2026 may be remembered not just as a bad period, but as the point when DeFi underwent a fundamental asset risk repricing, where security became a persistent,隐性 tax on all on-chain activity.

Foresight News07/01 08:03

$7.8 Billion in Theft and Losses Reveals the Truth: Security Costs Have Become an Unavoidable Liquidity Tax for DeFi

Foresight News07/01 08:03

Cross-Chain Bridges Actively Adapt, LI.FI Leverages Intent Architecture to Become the Liquidity Hub for TradFi Institutions

Cross-Chain Bridge LI.FI Transforms with Intents Architecture to Serve as Liquidity Hub for TradFi Institutions Facing declining cross-chain transaction volumes and overall crypto market liquidity, cross-chain bridge protocol LI.FI is proactively shifting its strategy. Moving beyond its role as a "liquidity transfer protocol," LI.FI is targeting new assets, clients, and operational systems. Key to this transformation is the launch of LI.FI Intents, an intent-based execution architecture. This product positions itself as a foundational layer for stablecoin payments, Real World Assets (RWA), and compliant on-chain liquidity, catering specifically to fintech companies, neobanks, wallets, and regulated financial institutions. LI.FI Intents simplifies user experience by offering a turnkey solution. It leverages a solver network for market-maker level execution, enabling precise cross-chain swaps (e.g., between USDC and USDT) without users managing gas tokens or complex blockchain steps. It lowers barriers to entry by integrating with applications like Jumper and Rabby, allowing enterprise users to bypass direct wallet interactions for transactions like payments and asset transfers. The architecture emphasizes compliance. Its network consists of verified legal entities, and enterprises can review and approve orders within their compliance frameworks before processing. All interacting wallets undergo OFAC screening. For ecosystem coverage, LI.FI Intents supports major networks including EVM chains, Solana, and Tron, mitigating risks associated with single-chain dependency. In essence, as tokenized assets like RWAs gain traction, LI.FI Intents focuses on efficiently integrating stablecoin payments and compliant liquidity into enterprise ecosystems. By automating complex execution steps—allowing users to simply declare their intent (the "destination")—it aims to enhance operational efficiency and capital utilization for institutional clients.

Odaily星球日报06/03 06:07

Cross-Chain Bridges Actively Adapt, LI.FI Leverages Intent Architecture to Become the Liquidity Hub for TradFi Institutions

Odaily星球日报06/03 06:07

DeFi Has Reached Its Most Dangerous Moment: The Real Vulnerabilities Are Not in the Code

DeFi in Peril: The Real Vulnerability Isn't in the Code April 2026 marked a paradigm shift in DeFi security, with over $625 million lost across 30 incidents—the worst month in crypto history by event count. Crucially, none of the major exploits (Drift Protocol: $285M, KelpDAO: $292M, Wasabi Protocol: $4.5M) resulted from smart contract vulnerabilities. Instead, failures occurred in the operational "plumbing": social engineering to compromise multi-signature councils, a single-point-of-failure 1-of-1 bridge validator, and stolen admin private keys. These events expose a fundamental misalignment: the industry's security model has long focused on code audits, while the actual attack surface has shifted to privileged access points and off-chain infrastructure. The article introduces the term "OpenFi" to describe this reality: permissionless, on-chain, yet operationally dependent on trusted third parties (admins, validators, oracles) at key junctures. The KelpDAO exploit vividly demonstrated asymmetric "contagion risk." A configuration error in a smaller protocol triggered a panic, causing approximately $13.2 billion in outflows from larger, unaffected protocols like Aave within 48 hours, as users fled uncertain collateral. The core dilemma is the double-edged sword of centralization. Operational levers like emergency councils (e.g., Arbitrum freezing stolen funds post-KelpDAO) enable crisis response but also create catastrophic attack surfaces if compromised (e.g., Drift). The path forward demands radical honesty: protocols must clearly disclose their trust assumptions, operational levers, and failure modes. The industry must treat operational security (key management, configurations, incident response) with the same rigor as code security. Survival depends on building systems whose risks can be understood, priced, and insured, moving beyond the outdated "code is law" mantra to a mature model of disclosed and managed trust.

链捕手05/25 15:17

DeFi Has Reached Its Most Dangerous Moment: The Real Vulnerabilities Are Not in the Code

链捕手05/25 15:17

$292 Million KelpDAO Cross-Chain Bridge Hack: Who Should Foot the Bill?

On April 18, 2026, an attacker stole 116,500 rsETH (worth ~$292M) from KelpDAO’s cross-chain bridge in 46 minutes—the largest DeFi exploit of 2026. The stolen assets were deposited into Aave V3 as collateral, causing $177–200M in bad debt and triggering a cascade of losses across nine DeFi protocols. Aave’s TVL dropped by ~$6B overnight. This legal analysis argues that KelpDAO and LayerZero Labs share concurrent liability, with fault apportioned 60%/40%. KelpDAO negligently configured its bridge with a 1-of-1 decentralized verifier network (DVN)—a single point of failure—despite LayerZero’s explicit recommendation of a 2-of-3 setup. LayerZero, which operated the compromised DVN, failed to secure its RPC infrastructure against a known poisoning attack vector. Both protocols’ terms of service cap liability at $200 (KelpDAO) or $50 (LayerZero), but these limits are likely unenforceable due to unconscionability, gross negligence exceptions, and potential securities law invalidation (if rsETH is deemed a security under the Howey test). Aave’s governance also faces fiduciary duty claims for raising rsETH’s loan-to-value ratio to 93%—far above competitors’ 72–75%—without adequately assessing bridge risks, amplifying the systemic fallout. Practical recovery targets include LayerZero Labs (a registered Canadian entity), KelpDAO’s founders, auditors, and identifiable Aave governance delegates. The incident underscores escalating legal risks for DeFi protocols, infrastructure providers, and governance participants.

marsbit04/24 06:25

$292 Million KelpDAO Cross-Chain Bridge Hack: Who Should Foot the Bill?

marsbit04/24 06:25

The $290 Million Deficit: A Three-Way Game Between Aave, L0, and Kelp—Who Should Foot the Bill?

An incident involving the theft of 116,500 rsETH (worth approximately $290 million) from Kelp DAO’s cross-chain bridge contract has triggered a complex dispute over responsibility and compensation among Kelp DAO, LayerZero, and Aave. The attack occurred due to a compromised RPC provider used by LayerZero’s Decentralized Verifier Network (DVN). Since Kelp DAO’s bridge used a 1/1 DVN configuration—a single point of failure—the attacker successfully forged a cross-chain message, leading to the unauthorized release of rsETH tokens from the mainnet. These genuine tokens were then deposited into Aave and other lending platforms to borrow WETH, enabling the attacker to exit with the funds. Responsibility is attributed primarily to Kelp DAO for its risky 1/1 DVN setup. LayerZero bears secondary responsibility for permitting such a vulnerable configuration in its protocol layer. Aave also shares indirect blame for over-collateralizing rsETH and other Liquid Restaking Token (LRT) assets without adequate ongoing risk oversight. Kelp DAO lacks sufficient funds to cover the loss, shifting focus to the deeper-pocketed players: LayerZero, whose cross-chain ecosystem and reputation are at risk, and Aave, which faces massive bad loans and declining Total Value Locked (TVL). Aave has asserted that mainnet rsETH remains fully backed, implying it expects Kelp DAO to allow redemption of underlying ETH. This approach would preserve Aave’s mainnet positions but invalidate Layer2 rsETH, damaging LayerZero’s cross-chain credibility. Potential solutions include: - A universal 18.5% haircut on all rsETH holders, causing significant Aave bad debt. - Writing off Layer2 rsETH entirely, protecting Aave mainnet but harming LayerZero and Kelp DAO. - Negotiating a bounty with the hacker for partial fund return. - A joint bailout, possibly led by LayerZero’s ecosystem fund, given its long-term stake in the cross-chain ecosystem. The situation remains unresolved as the parties negotiate, but prolonged delay risks broader DeFi instability, including potential liquidity crises and loss of confidence in LRT and cross-chain infrastructures.

Odaily星球日报04/20 08:52

The $290 Million Deficit: A Three-Way Game Between Aave, L0, and Kelp—Who Should Foot the Bill?

Odaily星球日报04/20 08:52

活动图片