$30 Billion DeFi Capital Exodus: LayerZero Stumbles, Chainlink Feasts

marsbitPublicado em 2026-05-13Última atualização em 2026-05-13

Resumo

Following the major DeFi security incident involving Kelp DAO, a significant migration of funds is underway from the cross-chain protocol LayerZero to Chainlink's CCIP (Cross-Chain Interoperability Protocol). Over $30 billion in Total Value Locked (TVL) from protocols like Kelp DAO, Solv Protocol, Re, and Tydro has moved to Chainlink in the past week, driven by security concerns. LayerZero is facing a severe trust crisis after the attack. Initially denying responsibility, LayerZero Labs has now issued a public apology, acknowledging management oversights. These include a vulnerable "1/1" single-node configuration for its Decentralized Verification Network (DVN) and past misuse of a multi-signature wallet by a team member. The protocol's weekly bridge volume has slumped to near-historic lows of around $470 million. In contrast, Chainlink is experiencing a surge in adoption and activity. Its independent active addresses recently hit multi-month highs, and whales have been accumulating LINK tokens. Beyond DeFi, Chainlink is securing partnerships with traditional finance giants like DTCC, European stock exchange operator SIX Group, and asset manager Amundi. While LayerZero has announced security upgrades—such as migrating to stronger multi-signature configurations and developing a second DVN client—and contributed to a rescue fund, the event underscores that security is becoming a decisive competitive factor as DeFi matures.

Author: Nancy, PANews

With several leading protocols stepping in to inject capital, quickly covering the funding gap and advancing on-chain recovery, the rescue efforts for the Kelp DAO attack incident have recently seen substantial progress. However, compared to the financial repairs, the harder thing to restore remains market trust.

At the center of this vortex, cross-chain leader LayerZero is facing accelerating withdrawals from many protocols and was forced to make a dramatic shift in attitude within just a few weeks—from initially shifting blame and denying responsibility to now publicly apologizing and initiating rectifications. Meanwhile, Chainlink has unexpectedly become a beneficiary of this crisis, with its CCIP protocol absorbing a large portion of migrating liquidity, showing notable growth in on-chain data.

Securing $30 Billion in Migration in a Single Week, Chainlink Reaps Security Dividends

As the largest DeFi security incident to date in 2026, the Kelp DAO attack has accelerated the migration of on-chain liquidity.

As LayerZero's security controversy continues to ferment, an increasing number of DeFi protocols are reevaluating cross-chain risks and proactively seeking more reliable havens. Over the past week, Chainlink has intensively announced multiple migration cases.

On May 9, Chainlink officially disclosed that four protocols, including Kelp DAO, Solv Protocol, Re, and Tydro, had recently abandoned their original cross-chain bridge or oracle solutions and migrated to Chainlink CCIP. The combined TVL of these related protocols exceeds $30 billion. The official even specifically added the phrase "The Great Migration" to hype this ecosystem shift, revealing strong competitive undertones.

Behind this migration wave is a realignment centered on security.

And besides DeFi protocols realigning due to security concerns, Chainlink has also been continuously gaining favor from traditional financial institutions and crypto projects in recent months.

In March of this year, Coinbase directly put its exchange market data on-chain for the first time via Chainlink's newly launched DataLink service; Europe's largest asset management firm, Amundi, collaborated with Spiko to launch a tokenized public fund based on Chainlink.

In April, OpenAssets formed a strategic partnership with Chainlink, launching an asset tokenization infrastructure solution for institutions; major European stock exchange operator SIX Group partnered with Chainlink to push Swiss and Spanish stock market data on-chain; AWS Marketplace listed Chainlink data services, connecting traditional cloud and blockchain.

In May, the US Depository Trust & Clearing Corporation (DTCC) announced the introduction of Chainlink to build a blockchain collateral management platform, aiming to achieve near-real-time settlement around the clock; Huma Finance partnered with Chainlink to introduce institutional-grade yield products into the multi-chain ecosystem.

Accompanying the ongoing ecosystem expansion, Chainlink's on-chain activity has also noticeably heated up. According to Santiment monitoring, Chainlink's number of unique active addresses broke 282,000 and 264,000 on May 9 and 10, respectively, hitting the highest records since September 2025, and noted this was primarily influenced by the recent large-scale migration of DeFi protocol infrastructure.

Meanwhile, official Chainlink data shows that the total value of its cross-chain tokens has exceeded $61.8 billion, with CCIP transaction volume reaching $19.5 billion.

Market confidence is also reflected in changes in LINK token holdings. According to Santiment monitoring earlier this month, over the past month, Chainlink whale and shark addresses holding between 100,000 and 10 million LINK cumulatively added 32.93 million LINK. Historically, this has often been a strong bullish signal. Over the past 30 days, LINK has risen approximately 19.7%.

LayerZero Faces Trust Crisis, Officials Issue Emergency Apology and Overhaul

Currently, LayerZero is mired in a trust crisis.

According to DefiLlama data, LayerZero's weekly Bridge transaction volume has now declined to about $470 million, approaching historical lows. This attack incident has plunged LayerZero into a trust crisis.

In the early stages of the hack, Kelp DAO attributed the vulnerability exploit to LayerZero's security issues. Subsequently, LayerZero quickly denied responsibility, stating that multiple accusations by Kelp DAO in the rsETH security incident were completely false.

But the controversy did not subside. Last week, LayerZero Labs co-founder and CEO Bryan Pellegrino engaged in heated debates with several security researchers in the ETHSecurity Community Telegram group.

The focal point of contention is that LayerZero Labs could immediately upgrade the default library contract without a timelock, theoretically allowing forged cross-chain messages. This exposed over $3 billion in LZ OFT assets to potential risk for a period. Security researcher Banteg pointed out that several mainstream projects, including Ethena and EtherFi, were still using this default library weeks ago, and about $178 million in assets remain exposed to risk.

Simultaneously, on-chain data also showed that LayerZero's multi-signature address had conducted Meme coin trading, DEX swaps, and cross-chain bridging operations unrelated to multi-signature duties, further raising community concerns about key security. In response, Bryan admitted that related operations were indeed performed by multi-signature team members but denied they constituted "Meme coin speculation trading," claiming the purpose was merely "testing PEPE OFT functionality," and stated that the involved members had been removed.

To mitigate risks, Bryan also publicly advised project teams to promptly adopt a "fixed configuration" to replace the default configuration. Subsequently, Banteg published a list of LayerZero projects still using the default library contract and called on related protocols to migrate as soon as possible.

These remarks quickly sparked industry discussion and skepticism. Chainlink Strategy Lead Zach Rynes had previously criticized LayerZero Labs, stating that its multi-signature keys had long suffered from serious OPSEC (operational security) failures, directly exposing tens of billions in OFT assets to security risks. He further stated that if LayerZero and the industry had truly heeded the persistent warnings from security researchers over the past few years, such attack incidents could have been entirely avoided.

Facing market舆论 and ongoing ecosystem bleeding, LayerZero's attitude shifted noticeably. On May 9, LayerZero officially released a public apology statement, addressing the security incidents and communication issues over the past three weeks.

LayerZero Labs stated that the internal RPC it used had been attacked by the Lazarus Group over the past three weeks, compromising the authenticity source of its DVN (Decentralized Verification Network), while external RPC providers suffered DDoS attacks. The incident affected only 0.14% of applications and approximately 0.36% of asset value, the LayerZero protocol itself was unaffected, and over $9 billion in assets continued normal cross-chain flow after the incident.

However, LayerZero Labs also acknowledged for the first time that it was responsible for management oversight in previously allowing DVNs to provide security for high-value transactions with a "1/1" single-node configuration, which posed a single point of failure risk. The official also disclosed that three and a half years ago, a multi-signature signer mistakenly used a multi-signature hardware wallet for personal transactions. That signer has been removed, and the relevant wallet has been rotated.

Regarding subsequent rectifications, LayerZero Labs announced a series of security upgrade measures, including: already ceasing services for the 1/1 DVN configuration, currently migrating all path default configurations to a 5/5 multi-signature setup with a minimum of 3/3; developing a second DVN client based on Rust to achieve client diversity; launching the dedicated multi-signature tool OneSig to enhance signature security; and launching the unified management platform Console for asset issuance configuration and abnormal behavior detection.

Additionally, LayerZero also contributed over 10,000 ETH to this DeFi United rescue effort, of which 5,000 ETH will be used for the fund, and the remaining 5,000 ETH will be reserved for Aave.

Despite the escalating controversy, LayerZero has not completely lost its market. Major assets, including Ethena's USDe product, EtherFi's weETH asset, and BitGo's WBTC, continue to use LayerZero's OFT standard.

Every major security crisis triggers a redistribution of liquidity and discourse power. As the crypto industry increasingly moves towards mainstream financial markets, the criteria for evaluating underlying infrastructure will become ever more stringent, with security capabilities becoming one of the core competitive advantages.

Perguntas relacionadas

QWhat was the immediate consequence of the Kelp DAO hack on the cross-chain infrastructure landscape?

AIt triggered a rapid migration of DeFi liquidity away from LayerZero due to security concerns, with over $30 billion in TVL from protocols like Kelp DAO moving to Chainlink's CCIP within a week.

QAccording to the article, what were two key security issues highlighted by researchers regarding LayerZero?

AFirst, LayerZero's default library contract, which could be upgraded instantly without a timelock, potentially allowing forged cross-chain messages. Second, suspicious non-multisig-related activities from a multisig signer address, raising concerns about key security.

QHow did Chainlink's on-chain activity and LINK token react to the migration trend mentioned in the article?

AChainlink's daily active unique addresses surged to over 282,000 and 264,000, the highest since September 2025. Furthermore, whales and sharks holding 100k to 10M LINK accumulated over 32.9 million LINK in a month, while the LINK token price rose approximately 19.7% in 30 days.

QWhat specific corrective measures did LayerZero announce in its public apology on May 9th?

ALayerZero announced several measures: stopping service for 1/1 DVN configurations, migrating all paths to at least 3/3 or 5/5 multisig setups, developing a second DVN client in Rust for client diversity, launching a dedicated multisig tool called OneSig, and releasing a management platform called Console for configuration and anomaly detection.

QDespite the crisis, which major assets and protocols were mentioned as still continuing to use LayerZero's technology?

AMajor assets and protocols continuing to use LayerZero's OFT standard include Ethena's USDe, EtherFi's weETH, and BitGo's WBTC.

Leituras Relacionadas

$2 Trillion: Countdown to AI's Largest IPO in History

The countdown for the largest IPO in AI history, a potential $2 trillion listing for Anthropic, is underway for October. The staggering valuation, reportedly projected by several investors, contrasts with the company's own internal restraint on setting a public target. Founded five years ago by former OpenAI core members, Anthropic's growth has been meteoric. Annual recurring revenue (ARR) surged from ~$9B in late 2025 to $47B by May 2026, with Q2 2026 revenue of $11.5B marking a 14x year-over-year increase. Bank valuations are even based on internal 2028 revenue forecasts of $190-200B. A key growth driver is Claude Code, its AI coding assistant. Its ARR quintupled in five months to $2.5B by February 2026, now constituting nearly 20% of total revenue. Surveys indicate Anthropic commands roughly 40% of enterprise LLM spending, doubling OpenAI's share in programming-specific use. However, alongside this explosive growth, reports detail significant internal cultural strife. Critics describe a divisive "priesthood" of PhD executives, led by CEO Dario Amodei, who promote a "save humanity" narrative that some employees find cult-like and alienating. This has reportedly created a demoralized workforce and a covert "underground network" of dissent among engineers torn between lucrative pre-IPO equity and a toxic work environment. Anthropic now faces a pivotal paradox: pursuing its mission of "safe" AI requires immense capital for compute, yet that capital demands relentless commercial growth. As it approaches its historic IPO, the company must navigate intense regulatory scrutiny, soaring operational costs, and internal tensions—any of which could destabilize its post-listing trajectory, much like SpaceX's significant post-IPO stock drop. The stage is set for a defining moment in tech history.

marsbitHá 59m

$2 Trillion: Countdown to AI's Largest IPO in History

marsbitHá 59m

AI Boosting Efficiency and Cutting Costs Makes VC Increasingly Expensive

"AI for Cost Reduction Makes VC Funding More Expensive" Despite the "cost-reduction and efficiency" narrative of AI, venture capital (VC) investment in the AI sector is becoming increasingly costly. While AI tools lower the initial costs for many startups—with team sizes shrinking across funding stages—the market is polarizing. For top-tier AI teams, especially those from leading companies like Google and OpenAI, funding rounds are now larger and valuations are higher than ever at the seed and early stages. For example, new ventures by prominent researchers are securing billions in funding with valuations reaching tens of billions before having a mature product. This creates a "barbell" market: lightweight startups need less capital, while elite AI firms attract massive investments early on. This dynamic raises the cost for VCs to acquire and maintain meaningful ownership stakes. As valuations soar early, securing the same equity percentage requires significantly larger capital commitments. VCs must now invest more upfront and reserve substantial funds for follow-on rounds to avoid dilution, prompting large firms like Accel and a16z to raise massive new funds. Consequently, capital is concentrating intensely in a few perceived winners like OpenAI and Anthropic, widening the gap between large and small VC funds. While high valuations bake in future growth expectations, they also compress potential returns, demanding that portfolio companies achieve unprecedented scale. For major VCs, the core strategy is clear: secure early positions in potential winners and maintain the capital to keep investing as valuations rapidly escalate.

marsbitHá 1h

AI Boosting Efficiency and Cutting Costs Makes VC Increasingly Expensive

marsbitHá 1h

An Eight-Year Investment Takes a Sharp Turn: Why Did Ethereum Suddenly Abandon Poseidon?

On August 13, Ethereum researcher Justin Drake announced a significant shift in Ethereum's Layer-1 cryptographic roadmap: abandoning the SNARK-friendly hash function Poseidon in favor of traditional functions like SHA2 or BLAKE2. This decision ends eight years of research and investment, marking a major revision to the post-quantum security strategy. Poseidon, introduced in 2019, was highly efficient for zkRollups and zkVMs within SNARK circuits. However, its need for prolonged cryptanalysis and the pressing timeline for quantum resistance revealed limitations. Recent breakthroughs in SNARK design, specifically using binary fields, now enable traditional, battle-tested hash functions to perform as efficiently as Poseidon within SNARKs. Benchmarks show modern laptops can now verify over a million traditional hash calls per second. This change is partly driven by accelerated concerns over quantum computing threats. Reports warn that "Cryptographically Relevant Quantum Computers" could break current blockchain signatures like ECDSA by the early 2030s, risking trillions in assets. Ethereum's response focuses on hash-based post-quantum signature schemes, deemed more quantum-resistant than some lattice-based alternatives under pressure from AI cryptanalysis. Ethereum's updated post-quantum roadmap targets a production-ready "leanVM" for signature aggregation by 2027, with full deployment across consensus, execution, and data layers by 2028. The shift to mature hash functions like SHA2 reduces reliance on newer algorithms and aligns with the goal of using widely analyzed cryptographic primitives. Other major blockchains are also preparing. Solana's core teams have independently chosen the NIST-standardized Falcon signature scheme for its compact size. Starknet plans a phased migration, starting with replacing its Pedersen hash with BLAKE2. Ethereum's move signifies a strategic pivot towards proven security foundations for the quantum era.

marsbitHá 2h

An Eight-Year Investment Takes a Sharp Turn: Why Did Ethereum Suddenly Abandon Poseidon?

marsbitHá 2h

Programmers Worldwide Are Wasting Money on Anthropic! The Company Can't Stand It Anymore

Anthropic recently published guidelines to help developers using Claude Code reduce unnecessary token costs. The key recommendations include: 1) Clear (/clear) conversations after completing a task to avoid carrying irrelevant file reads and command outputs into the next task. 2) Set the model and reasoning effort level at the start of a session, as switching mid-session invalidates the prompt cache, requiring a full-price recalculation of the entire dialog history. 3) Attach files using @ references instead of typing paths manually to avoid extra tool calls and searches that bloat the context. 4) Add quiet flags to verbose commands (e.g., in CLAUDE.md) to minimize lengthy output in the dialog history. 5) Use /compact while the session cache is still warm (before breaks) to compress the dialog at one-tenth the cost. 6) Offload large-output tasks to a sub-agent, which runs in an isolated context and only returns conclusions, preventing intermediate outputs from polluting the main dialog. The article explains token pricing: input tokens (prefill) are processed in parallel, while output tokens (decode) are generated serially, making output tokens five times more expensive. Caching is crucial for savings—if a request's prefix (system prompt, CLAUDE.md, dialog history) matches the previous one byte-for-byte, reading it costs only 10% of the standard input price. However, cache invalidation occurs when changing models, effort levels, fast mode, compressing dialogs, after cache expiration, or when resuming old sessions. Dialog history also grows quadratically (O(n²)) as file contents and command outputs accumulate, increasing costs per round. Proactive context management—like isolating noisy tasks, using /rewind to trim unproductive turns, and task-based session clearing—is becoming an essential skill for cost-effective AI-assisted development.

marsbitHá 4h

Programmers Worldwide Are Wasting Money on Anthropic! The Company Can't Stand It Anymore

marsbitHá 4h

Pax Silica vs. WAICO: The US Wants to Prohibit Europe from Using Chinese Artificial Intelligence

The United States is preparing to demand that European and other partners abandon Chinese artificial intelligence initiatives, threatening exclusion from the American-led "Pax Silica" coalition, according to a leaked U.S. State Department document. This ultimatum forces signatories of the "AI Opportunity Statement" to choose between the Western technological ecosystem and alternative frameworks, with China not explicitly named but clearly targeted. Pax Silica is a U.S. strategy for AI and semiconductor hegemony, launched in late 2025. Its European presence expanded significantly in mid-2026. Concurrently, China, Russia, and 27 other nations established the World AI Cooperation Organization (WAICO) in July 2026 as an independent intergovernmental platform promoting AI governance based on UN principles. This situation creates a difficult choice, especially for European nations balancing strategic autonomy with dependence on U.S. tech and security. It also pressures Global South countries with pragmatic ties to both Washington and Beijing. The formation of competing blocks risks fragmenting the global tech landscape, forcing companies to split supply chains, increasing costs, and potentially leading to incompatible standards and protocols. The era of open globalization in AI may be ending, replaced by geopolitical confrontation where technological sovereignty trumps economic efficiency. The decisions made will shape the global digital economy for decades.

cryptonews.ruHá 6h

Pax Silica vs. WAICO: The US Wants to Prohibit Europe from Using Chinese Artificial Intelligence

cryptonews.ruHá 6h

Trading

Spot
活动图片