Following the KelpDAO Hack: $40 Billion in Assets Flee LayerZero, Chainlink Emerges as the Primary 'Beneficiary'

marsbitОпубліковано о 2026-05-19Востаннє оновлено о 2026-05-19

Анотація

Following a major security breach in April where KelpDAO's bridge using LayerZero was attacked for approximately $292 million, a significant shift is underway in the cross-chain infrastructure landscape. An estimated $40 billion in assets is in the process of migrating or has already migrated from LayerZero to Chainlink's Cross-Chain Interoperability Protocol (CCIP). The attack exploited a single-point-of-failure vulnerability due to KelpDAO's 1-of-1 validator configuration within the LayerZero network. Attackers corrupted RPC nodes and used DDoS attacks to force the system to rely on compromised nodes, allowing fraudulent messages. While LayerZero acknowledged a serious error in allowing its validator network to service high-value transactions with such a configuration, the incident highlighted critical security risks. This triggered a rapid migration wave. Starting with KelpDAO on May 6th, several major protocols—including Solv Protocol, Re, Tydro, Kraken, and Lombard—announced switching their cross-chain infrastructure exclusively to Chainlink CCIP. The combined value of these migrations is estimated to be around $40 billion. This movement followed earlier major adoptions by Coinbase (in late 2025) and Circle (in early 2024). Market sentiment reflected this shift, with LINK's price showing relative stability while ZRO (LayerZero's token) declined significantly. Data indicates a net outflow of approximately $20.1 billion from the LayerZero network over 30 days. The migr...

Since the cross-chain bridge of KelpDAO suffered an attack of approximately $292 million in April this year, the security landscape of cross-chain infrastructure has been undergoing a dramatic reshuffle. Statistics show that about $40 billion in assets have completed or are in the process of migrating from LayerZero to Chainlink's Cross-Chain Interoperability Protocol (CCIP).

The attack occurred in the early hours of April 19. The attacker invoked a function of the LayerZero Endpoint V2 contract, triggering the KelpDAO bridging contract to release approximately 116,500 rsETH, worth about $292 million. The protocol's emergency pause mechanism subsequently prevented further losses of around $100 million.

Following the attack, LayerZero issued a statement suggesting that the initial assessment pointed to a highly sophisticated state actor, suspected to be TraderTraitor, a subgroup of the North Korean Lazarus Group.

The core of the attack method involved poisoning the RPC nodes relied upon by the LayerZero decentralized validator network and forcing a system failover to already compromised nodes through a DDoS attack, allowing forged messages to pass through. The central point of controversy is that KelpDAO was using a 1-of-1 single validator configuration at the time, which, once exploited, led to a single point of failure.

LayerZero acknowledged that allowing its official validator network to service high-value transactions with a 1/1 configuration was a serious mistake and announced the cessation of signing messages for single validator setups. KelpDAO pointed out that this configuration had appeared as a default setting in LayerZero's deployment code. Regardless of where the responsibility lies, this attack exposed the vulnerability of cross-chain message verification under specific configurations.

A wave of migrations began shortly after. On May 6, the victim, KelpDAO, took the lead in announcing its abandonment of LayerZero, fully transitioning its rsETH cross-chain facilities to Chainlink CCIP, becoming the first major protocol to leave.

Two days later, the Bitcoin staking protocol Solv Protocol switched the cross-chain infrastructure for its SolvBTC and xSolvBTC, with a total value exceeding $700 million, to CCIP, covering all supported routes.

On the same day, the decentralized reinsurance protocol Re also migrated the cross-chain solution for its deposit token reUSD to CCIP, designating it as the sole cross-chain solution. The non-custodial lending protocol Tydro was also among the first batch to migrate.

On May 14, Kraken announced replacing LayerZero with Chainlink CCIP as the exclusive cross-chain service for its wrapped crypto assets, including wrapped Bitcoin kBTC, covering multiple blockchains such as Ink, Ethereum, and Optimism. On the 16th, Lombard announced abandoning LayerZero, migrating over $1 billion worth of Bitcoin-backed assets to CCIP, adopting a burn-and-mint cross-chain token standard.

According to DefiLlama data, if only counting the current total value locked (TVL) of the main DeFi protocols, the combined scale of these five exceeds $3.4 billion. Factoring in institutional wrapped assets, the overall migration scale reaches approximately $4 billion.

Coinbase had already chosen CCIP as the exclusive interoperability provider for all its wrapped assets as early as December 2025, covering assets like cbBTC, cbETH, cbDOGE, cbLTC, cbADA, and cbXRP, with a total market capitalization of about $7 billion at that time. In January 2024, Circle had also integrated with CCIP to support multi-chain transfers of USDC.

The market's reaction to this shift in trust was directly reflected in token price movements.

According to CoinMarketCap data, LINK has risen 2.73% over the past 30 days, trading at $9.6, with a market cap of $6.98 billion, steadily holding the 16th position in the crypto market. In contrast, ZRO fell 22.63% over the same period, trading at $1.34, with a market cap of $434 million, its ranking slipping to 92nd. LayerZero also faces additional pressure from the unlocking of over 25.71 million ZRO tokens on May 20, worth approximately $34.45 million, accounting for 5.07% of the circulating supply.

According to Dune data, the LayerZero network has seen a net outflow of approximately $2.01 billion over the past 30 days.

Behind the influx of protocols lies the significant difference in security architecture between Chainlink CCIP and LayerZero. Chainlink previously announced in April 2024 that CCIP had entered general availability, supporting blockchains like Arbitrum, Base, BNB Chain, and Ethereum.

Chainlink CCIP deeply integrates with the decentralized oracle network, consisting of multiple independent node operators forming an off-chain consensus layer to observe, verify, and report cross-chain events, supplemented by an independent risk management network providing additional monitoring and protection. Its token transfer mechanism includes built-in rate limiting and timelock upgrades, forming a defense-in-depth security model.

According to Dune data, the cumulative cross-chain token transfer value for Chainlink CCIP has exceeded $2 billion. Among them, the decentralized stablecoin GHO and USDC have the highest shares, reaching 22.4% and 20.2%, respectively, corresponding to amounts of approximately $531 million and $481 million.

In contrast, LayerZero employs a highly modular five-layer architecture, completely separating interfaces, validation, and execution, allowing developers to freely combine decentralized validator networks and configure validation thresholds. This design offers high flexibility but also requires application parties to actively choose and maintain security configurations.

The KelpDAO incident cast a spotlight on the fatal flaw of the single validator configuration. Protocols that had chosen the 1/1 configuration at the time accounted for as much as 47%, prompting many projects to quickly turn to CCIP, which defaults to decentralized validation and offers more comprehensive security controls.

On May 9, LayerZero published a letter of apology, acknowledging mishandling communication over the past three weeks and stating that it should have directly explained the situation earlier rather than prioritizing the completion of a post-mortem analysis report.

LayerZero emphasized that the protocol itself was not affected; rather, the internal RPC used by the LayerZero Labs DVN was poisoned by a data source, while external RPC providers suffered DDoS attacks. It admitted that allowing the Labs DVN to service high-value transactions as a 1/1 configuration was a serious error. The official team will soon release an official post-mortem analysis report in collaboration with external security partners.

Пов'язані питання

QWhat triggered the massive migration of approximately $40 billion in assets from LayerZero to Chainlink's CCIP?

AThe migration was triggered by a major security breach on April 19, where the KelpDAO bridge on LayerZero was exploited for roughly $292 million. The attack exposed vulnerabilities, particularly in the single-validator (1-of-1) configuration, leading to a loss of trust and prompting protocols to seek more secure alternatives.

QWhat was the core vulnerability exploited in the KelpDAO attack on LayerZero?

AThe core vulnerability was the use of a single-validator (1-of-1) configuration for message verification. Attackers poisoned the RPC node relied upon by LayerZero's decentralized validator network and conducted a DDoS attack to force the system to fail over to the compromised node, allowing fraudulent messages to be approved.

QWhich major protocols were mentioned as having migrated from LayerZero to Chainlink CCIP following the attack?

AMajor protocols that migrated include KelpDAO (rsETH), Solv Protocol (SolvBTC, xSolvBTC), Re (reUSD), Tydro, Kraken (for wrapped assets like kBTC), and Lombard (for over $1 billion in Bitcoin-backed assets). Coinbase had already selected CCIP in December 2025 for its wrapped assets.

QHow does Chainlink's CCIP security architecture fundamentally differ from LayerZero's approach?

AChainlink CCIP is built on a decentralized oracle network with multiple independent node operators forming an off-chain consensus layer for validating cross-chain events, complemented by a separate Risk Management Network. It features built-in safeguards like rate limits and timelocks. In contrast, LayerZero offers a highly modular architecture that separates interface, verification, and execution, giving developers flexibility to configure their own validator networks and security thresholds, which can introduce risk if not properly managed.

QWhat was the impact of the KelpDAO incident and subsequent migrations on the market value of LINK and ZRO tokens?

AAccording to the article, LINK (Chainlink's token) rose 2.73% over 30 days to $9.6, with a market cap of $6.98 billion. In contrast, ZRO (LayerZero's token) fell 22.63% to $1.34, with its market cap dropping to $434 million and its rank falling to 92nd. LayerZero also faced additional pressure from a token unlock scheduled for May 20.

Пов'язані матеріали

IOSG: After the Number of Developers Halved, Crypto Did Not Die

The crypto development community has undergone a significant transformation, with monthly active developers on GitHub halving from 45K in 2022 to approximately 23K by 2026. This decline is largely attributed to the departure of newcomers, whose roles were often tied to market-driven hype cycles like NFTs and forked DeFi protocols, leading to a 52% churn rate among those with less than a year of experience. However, the core of the industry has strengthened. Established developers with over two years of experience have reached a record high, contributing about 70% of the code. They are consolidating around ecosystems with genuine users and revenue, such as Bitcoin and Solana, while moving away from narrative-driven projects. The talent shift represents a "deleveraging" and an increase in core density. This core group has developed a unique skillset by operating in an environment of "code is law," with zero tolerance for error and no external recourse. They have learned to build trust and functional systems from the ground up without central authorities, as demonstrated by protocols like Uniswap and MakerDAO. These capabilities are now being repriced and leveraged in the AI era. The structural challenges of AI scaling—such as trust, coordination, and verification—mirror those long addressed in crypto. Examples include CoreWeave pivoting from GPU mining to AI compute, OpenSea's founder applying NFT market logic to AI model routing with OpenRouter, and projects like NEAR and Catena Labs transitioning crypto-native architectural and financial insights into AI infrastructure and agent banking. Key areas where crypto-bred skills are directly applicable to AI include: 1. **Compute Aggregation & Optimization**: Using token incentives and cryptographic verification (e.g., Proof of Sampling & Privacy) to create trusted, decentralized GPU networks, as seen with Hyperbolic. 2. **AI Governance & Incentive Design**: Applying economic mechanism design from DAOs and tokenomics to align the goals of multiple, fast-acting AI agents, a direction explored by EigenLayer's EigenCloud. 3. **AI Agent Autonomous Payments**: Leveraging stablecoins and programmable, permissionless blockchains to enable the micro-transactions required for AI agent economies, exemplified by protocols like x402. The role of the crypto builder is evolving from writing smart contracts to designing trust mechanisms for autonomous AI systems. This convergence is reflected in hiring trends at major firms and significant capital allocation from funds like Paradigm and a16z crypto, which are investing at the intersection of crypto and AI. Regional differences exist, with the US favoring foundational protocol innovation and Asia focusing on compliant application-layer integration, but the underlying trend is clear. The industry's "deleveraging" has not signaled its demise but rather a maturation, positioning its core builders to solve critical trust and coordination problems in the age of AI.

marsbit28 хв тому

IOSG: After the Number of Developers Halved, Crypto Did Not Die

marsbit28 хв тому

Currency and Stock Market Barometer: Strategy Invested Over $2 Billion to Buy Over 24,800 BTC Last Week; Bitmine's ETH Holdings Increase to 4.37% of Total Supply (May 19)

Crypto & Stock Market Watch: Institutional BTC Buying Surges, ETH Holdings Grow Major listed companies aggressively accumulated Bitcoin last week, with net purchases skyrocketing over 44x to $2.03 billion. Strategy (formerly MicroStrategy) led the charge, spending approximately $2.01 billion to buy 24,869 BTC, bringing its total holdings to 843,738 BTC. Overall, listed firms (excluding miners) now hold 1,113,841 BTC, valued at ~$86.16 billion. On the Ethereum front, Bitmine purchased 71,672 ETH in the past week. It now holds 5,278,462 ETH, worth $11.56 billion and representing 4.37% of ETH's total supply. A significant portion (4,712,917 ETH) is staked, generating an annualized yield of $289 million. Industry leaders note a divergence from the MicroStrategy model, with ETH treasury firms increasingly focusing on staking yields and simpler balance sheets. In traditional markets, Morgan Stanley warns of a potential significant U.S. stock market correction if bond yields and volatility continue rising. Investment giants like Berkshire Hathaway and Bridgewater adjusted portfolios in Q1, with Bridgewater notably increasing its stakes in chipmakers like Nvidia, Broadcom, and Micron while shedding software stocks. Among other crypto-focused public companies, Solana treasury firm Upexi reported a widened net loss of $109 million for its fiscal Q3, driven by a decline in its crypto holdings' value. Meanwhile, Hyperion DeFi, a HYPE token treasury company, reported a Q1 net profit of $8.8 million and increased its HYPE holdings past 2 million tokens.

marsbit28 хв тому

Currency and Stock Market Barometer: Strategy Invested Over $2 Billion to Buy Over 24,800 BTC Last Week; Bitmine's ETH Holdings Increase to 4.37% of Total Supply (May 19)

marsbit28 хв тому

Global Long-Term Bonds Break Down: The Fiscal Illusion of the Low-Interest Era is Collapsing

Global long-term bonds are experiencing a widespread breakdown, as the fiscal illusion of the low-interest-rate era collapses. Sovereign yields are hitting multi-year highs in the US, UK, Japan, and France, signaling a market repricing driven by a common reality: unsustainable debt and deficits outpacing economic growth, compounded by renewed inflationary pressures from energy shocks. The direct trigger is the blockade of the Strait of Hormuz, which has pushed oil prices higher and reignited inflation fears. This squeezes central bank policy space, with expectations shifting from future rate cuts to potential hikes. The core "fiscal Ponzi scheme" is becoming evident—governments rely on new debt to service existing obligations, but as growth lags and borrowing costs rise, investors demand higher yields. Key developments include the US 30-year yield surpassing 5% for the first time since 2007, with tepid auction demand; Japan's 30-year yield reaching 4%, threatening its long-standing low-rate financial system; and political paralysis in the UK and France making meaningful fiscal consolidation unlikely. The marginal buyer for US debt is also shifting from foreign central banks to more price-sensitive private investors. While debt managers may adjust issuance, fundamental drivers—deteriorating fiscal paths, persistent inflation, and constrained central banks—remain. The market is conclusively repricing the end of the low-interest-rate financing model for highly indebted developed economies.

marsbit55 хв тому

Global Long-Term Bonds Break Down: The Fiscal Illusion of the Low-Interest Era is Collapsing

marsbit55 хв тому

Торгівля

Спот
Ф'ючерси

Популярні статті

Як купити LINK

Ласкаво просимо до HTX.com! Ми зробили покупку ChainLink (LINK) простою та зручною. Дотримуйтесь нашої покрокової інструкції, щоб розпочати свою криптовалютну подорож.Крок 1: Створіть обліковий запис на HTXВикористовуйте свою електронну пошту або номер телефону, щоб зареєструвати обліковий запис на HTX безплатно. Пройдіть безпроблемну реєстрацію й отримайте доступ до всіх функцій.ЗареєструватисьКрок 2: Перейдіть до розділу Купити крипту і виберіть спосіб оплатиКредитна/дебетова картка: використовуйте вашу картку Visa або Mastercard, щоб миттєво купити ChainLink (LINK).Баланс: використовуйте кошти з балансу вашого рахунку HTX для безперешкодної торгівлі.Треті особи: ми додали популярні способи оплати, такі як Google Pay та Apple Pay, щоб підвищити зручність.P2P: Торгуйте безпосередньо з іншими користувачами на HTX.Позабіржова торгівля (OTC): ми пропонуємо індивідуальні послуги та конкурентні обмінні курси для трейдерів.Крок 3: Зберігайте свої ChainLink (LINK)Після придбання ChainLink (LINK) збережіть його у своєму обліковому записі на HTX. Крім того, ви можете відправити його в інше місце за допомогою блокчейн-переказу або використовувати його для торгівлі іншими криптовалютами.Крок 4: Торгівля ChainLink (LINK)Легко торгуйте ChainLink (LINK) на спотовому ринку HTX. Просто увійдіть до свого облікового запису, виберіть торгову пару, укладайте угоди та спостерігайте за ними в режимі реального часу. Ми пропонуємо зручний досвід як для початківців, так і для досвідчених трейдерів.

1.1k переглядів усьогоОпубліковано 2024.12.13Оновлено 2025.03.21

Як купити LINK

Обговорення

Ласкаво просимо до спільноти HTX. Тут ви можете бути в курсі останніх подій розвитку платформи та отримати доступ до професійної ринкової інформації. Нижче представлені думки користувачів щодо ціни LINK (LINK).

活动图片