$30 Billion DeFi Capital Exodus: LayerZero Stumbles, Chainlink Feasts

marsbitXuất bản vào 2026-05-13Cập nhật gần nhất vào 2026-05-13

Tóm tắt

Following the major DeFi security incident involving Kelp DAO, a significant migration of funds is underway from the cross-chain protocol LayerZero to Chainlink's CCIP (Cross-Chain Interoperability Protocol). Over $30 billion in Total Value Locked (TVL) from protocols like Kelp DAO, Solv Protocol, Re, and Tydro has moved to Chainlink in the past week, driven by security concerns. LayerZero is facing a severe trust crisis after the attack. Initially denying responsibility, LayerZero Labs has now issued a public apology, acknowledging management oversights. These include a vulnerable "1/1" single-node configuration for its Decentralized Verification Network (DVN) and past misuse of a multi-signature wallet by a team member. The protocol's weekly bridge volume has slumped to near-historic lows of around $470 million. In contrast, Chainlink is experiencing a surge in adoption and activity. Its independent active addresses recently hit multi-month highs, and whales have been accumulating LINK tokens. Beyond DeFi, Chainlink is securing partnerships with traditional finance giants like DTCC, European stock exchange operator SIX Group, and asset manager Amundi. While LayerZero has announced security upgrades—such as migrating to stronger multi-signature configurations and developing a second DVN client—and contributed to a rescue fund, the event underscores that security is becoming a decisive competitive factor as DeFi matures.

Author: Nancy, PANews

With several leading protocols stepping in to inject capital, quickly covering the funding gap and advancing on-chain recovery, the rescue efforts for the Kelp DAO attack incident have recently seen substantial progress. However, compared to the financial repairs, the harder thing to restore remains market trust.

At the center of this vortex, cross-chain leader LayerZero is facing accelerating withdrawals from many protocols and was forced to make a dramatic shift in attitude within just a few weeks—from initially shifting blame and denying responsibility to now publicly apologizing and initiating rectifications. Meanwhile, Chainlink has unexpectedly become a beneficiary of this crisis, with its CCIP protocol absorbing a large portion of migrating liquidity, showing notable growth in on-chain data.

Securing $30 Billion in Migration in a Single Week, Chainlink Reaps Security Dividends

As the largest DeFi security incident to date in 2026, the Kelp DAO attack has accelerated the migration of on-chain liquidity.

As LayerZero's security controversy continues to ferment, an increasing number of DeFi protocols are reevaluating cross-chain risks and proactively seeking more reliable havens. Over the past week, Chainlink has intensively announced multiple migration cases.

On May 9, Chainlink officially disclosed that four protocols, including Kelp DAO, Solv Protocol, Re, and Tydro, had recently abandoned their original cross-chain bridge or oracle solutions and migrated to Chainlink CCIP. The combined TVL of these related protocols exceeds $30 billion. The official even specifically added the phrase "The Great Migration" to hype this ecosystem shift, revealing strong competitive undertones.

Behind this migration wave is a realignment centered on security.

And besides DeFi protocols realigning due to security concerns, Chainlink has also been continuously gaining favor from traditional financial institutions and crypto projects in recent months.

In March of this year, Coinbase directly put its exchange market data on-chain for the first time via Chainlink's newly launched DataLink service; Europe's largest asset management firm, Amundi, collaborated with Spiko to launch a tokenized public fund based on Chainlink.

In April, OpenAssets formed a strategic partnership with Chainlink, launching an asset tokenization infrastructure solution for institutions; major European stock exchange operator SIX Group partnered with Chainlink to push Swiss and Spanish stock market data on-chain; AWS Marketplace listed Chainlink data services, connecting traditional cloud and blockchain.

In May, the US Depository Trust & Clearing Corporation (DTCC) announced the introduction of Chainlink to build a blockchain collateral management platform, aiming to achieve near-real-time settlement around the clock; Huma Finance partnered with Chainlink to introduce institutional-grade yield products into the multi-chain ecosystem.

Accompanying the ongoing ecosystem expansion, Chainlink's on-chain activity has also noticeably heated up. According to Santiment monitoring, Chainlink's number of unique active addresses broke 282,000 and 264,000 on May 9 and 10, respectively, hitting the highest records since September 2025, and noted this was primarily influenced by the recent large-scale migration of DeFi protocol infrastructure.

Meanwhile, official Chainlink data shows that the total value of its cross-chain tokens has exceeded $61.8 billion, with CCIP transaction volume reaching $19.5 billion.

Market confidence is also reflected in changes in LINK token holdings. According to Santiment monitoring earlier this month, over the past month, Chainlink whale and shark addresses holding between 100,000 and 10 million LINK cumulatively added 32.93 million LINK. Historically, this has often been a strong bullish signal. Over the past 30 days, LINK has risen approximately 19.7%.

LayerZero Faces Trust Crisis, Officials Issue Emergency Apology and Overhaul

Currently, LayerZero is mired in a trust crisis.

According to DefiLlama data, LayerZero's weekly Bridge transaction volume has now declined to about $470 million, approaching historical lows. This attack incident has plunged LayerZero into a trust crisis.

In the early stages of the hack, Kelp DAO attributed the vulnerability exploit to LayerZero's security issues. Subsequently, LayerZero quickly denied responsibility, stating that multiple accusations by Kelp DAO in the rsETH security incident were completely false.

But the controversy did not subside. Last week, LayerZero Labs co-founder and CEO Bryan Pellegrino engaged in heated debates with several security researchers in the ETHSecurity Community Telegram group.

The focal point of contention is that LayerZero Labs could immediately upgrade the default library contract without a timelock, theoretically allowing forged cross-chain messages. This exposed over $3 billion in LZ OFT assets to potential risk for a period. Security researcher Banteg pointed out that several mainstream projects, including Ethena and EtherFi, were still using this default library weeks ago, and about $178 million in assets remain exposed to risk.

Simultaneously, on-chain data also showed that LayerZero's multi-signature address had conducted Meme coin trading, DEX swaps, and cross-chain bridging operations unrelated to multi-signature duties, further raising community concerns about key security. In response, Bryan admitted that related operations were indeed performed by multi-signature team members but denied they constituted "Meme coin speculation trading," claiming the purpose was merely "testing PEPE OFT functionality," and stated that the involved members had been removed.

To mitigate risks, Bryan also publicly advised project teams to promptly adopt a "fixed configuration" to replace the default configuration. Subsequently, Banteg published a list of LayerZero projects still using the default library contract and called on related protocols to migrate as soon as possible.

These remarks quickly sparked industry discussion and skepticism. Chainlink Strategy Lead Zach Rynes had previously criticized LayerZero Labs, stating that its multi-signature keys had long suffered from serious OPSEC (operational security) failures, directly exposing tens of billions in OFT assets to security risks. He further stated that if LayerZero and the industry had truly heeded the persistent warnings from security researchers over the past few years, such attack incidents could have been entirely avoided.

Facing market舆论 and ongoing ecosystem bleeding, LayerZero's attitude shifted noticeably. On May 9, LayerZero officially released a public apology statement, addressing the security incidents and communication issues over the past three weeks.

LayerZero Labs stated that the internal RPC it used had been attacked by the Lazarus Group over the past three weeks, compromising the authenticity source of its DVN (Decentralized Verification Network), while external RPC providers suffered DDoS attacks. The incident affected only 0.14% of applications and approximately 0.36% of asset value, the LayerZero protocol itself was unaffected, and over $9 billion in assets continued normal cross-chain flow after the incident.

However, LayerZero Labs also acknowledged for the first time that it was responsible for management oversight in previously allowing DVNs to provide security for high-value transactions with a "1/1" single-node configuration, which posed a single point of failure risk. The official also disclosed that three and a half years ago, a multi-signature signer mistakenly used a multi-signature hardware wallet for personal transactions. That signer has been removed, and the relevant wallet has been rotated.

Regarding subsequent rectifications, LayerZero Labs announced a series of security upgrade measures, including: already ceasing services for the 1/1 DVN configuration, currently migrating all path default configurations to a 5/5 multi-signature setup with a minimum of 3/3; developing a second DVN client based on Rust to achieve client diversity; launching the dedicated multi-signature tool OneSig to enhance signature security; and launching the unified management platform Console for asset issuance configuration and abnormal behavior detection.

Additionally, LayerZero also contributed over 10,000 ETH to this DeFi United rescue effort, of which 5,000 ETH will be used for the fund, and the remaining 5,000 ETH will be reserved for Aave.

Despite the escalating controversy, LayerZero has not completely lost its market. Major assets, including Ethena's USDe product, EtherFi's weETH asset, and BitGo's WBTC, continue to use LayerZero's OFT standard.

Every major security crisis triggers a redistribution of liquidity and discourse power. As the crypto industry increasingly moves towards mainstream financial markets, the criteria for evaluating underlying infrastructure will become ever more stringent, with security capabilities becoming one of the core competitive advantages.

Câu hỏi Liên quan

QWhat was the immediate consequence of the Kelp DAO hack on the cross-chain infrastructure landscape?

AIt triggered a rapid migration of DeFi liquidity away from LayerZero due to security concerns, with over $30 billion in TVL from protocols like Kelp DAO moving to Chainlink's CCIP within a week.

QAccording to the article, what were two key security issues highlighted by researchers regarding LayerZero?

AFirst, LayerZero's default library contract, which could be upgraded instantly without a timelock, potentially allowing forged cross-chain messages. Second, suspicious non-multisig-related activities from a multisig signer address, raising concerns about key security.

QHow did Chainlink's on-chain activity and LINK token react to the migration trend mentioned in the article?

AChainlink's daily active unique addresses surged to over 282,000 and 264,000, the highest since September 2025. Furthermore, whales and sharks holding 100k to 10M LINK accumulated over 32.9 million LINK in a month, while the LINK token price rose approximately 19.7% in 30 days.

QWhat specific corrective measures did LayerZero announce in its public apology on May 9th?

ALayerZero announced several measures: stopping service for 1/1 DVN configurations, migrating all paths to at least 3/3 or 5/5 multisig setups, developing a second DVN client in Rust for client diversity, launching a dedicated multisig tool called OneSig, and releasing a management platform called Console for configuration and anomaly detection.

QDespite the crisis, which major assets and protocols were mentioned as still continuing to use LayerZero's technology?

AMajor assets and protocols continuing to use LayerZero's OFT standard include Ethena's USDe, EtherFi's weETH, and BitGo's WBTC.

Nội dung Liên quan

Gần 3 triệu fan hâm mộ, "nữ thần thiện nguyện" đều do AI tổng hợp, làm giả trại mồ côi xuyên biên giới, sự nghiệp "làm từ thiện giả" sụp đổ chỉ sau một đêm

Cô gái người Úc có tên Lily Jay (tên thật Lily Jay Hinson) đã gây chấn động mạng xã hội khi bị phát hiện sử dụng AI để tạo ra một vụ lừa đảo từ thiện quy mô lớn. Với gần 3 triệu người theo dõi trên Instagram, cô xây dựng hình ảnh một tín đồ Hồi giáo ngoan đạo và tích cực thông qua "Quỹ Lily Jay", tuyên bố xây dựng nhà thờ Hồi giáo, cứu trợ trẻ mồ côi ở Uganda, Sudan, Nepal và phân phát bánh mì cho người tị nạn ở Gaza. Tuy nhiên, điều tra từ ABC News Verify đã vạch trần hàng loạt bằng chứng giả mạo: video khánh thành trại trẻ mồ côi ở Uganda với những đứa trẻ cầm kẹo, biểu ngữ và chính người phụ nữ trong video đều do AI tạo ra, kể cả chi tiết lỗi chính tả trên áo phông. Hình ảnh nhận giải thưởng nhân đạo cũng chứa watermark của ChatGPT. Quỹ này thậm chí không đăng ký hoạt động hợp pháp tại Uganda và không có tên trong sổ đăng ký từ thiện ở Úc, đồng thời đã giấu một dòng tuyên bố "không phải là tổ chức từ thiện" trên website. Hoạt động của quỹ đầy nghi vấn: trụ sở đặt ở Kosovo, cá nhân Lily Jay sống ở Cyprus và không phải là giám đốc quỹ. Sau khi bị ABC chất vấn, trang web đã gỡ video giả và nút quyên góp đối với truy cập từ Úc, nhưng vẫn để mở cho người dùng quốc tế. Chuyên gia cảnh báo đây là kiểu lừa đảo nguy hiểm, lợi dụng lòng trắc ẩn và sự tin tưởng. Vụ việc gióng lên hồi chuông cảnh tỉnh về việc AI có thể bị lạm dụng để tạo ra những câu chuyện giả tưởng hoàn hảo, đánh cắp sự thiện nguyện của công chúng trong thời đại số.

marsbit14 phút trước

Gần 3 triệu fan hâm mộ, "nữ thần thiện nguyện" đều do AI tổng hợp, làm giả trại mồ côi xuyên biên giới, sự nghiệp "làm từ thiện giả" sụp đổ chỉ sau một đêm

marsbit14 phút trước

L2 'Tái hiệu chuẩn': Khi L1 Trở Thành Rollup Của Chính Mình, Cục Diện Cuối Cùng Của Ethereum Là Gì?

"L2 Hiệu chỉnh lại": Khi L1 trở thành Rollup của chính nó, tương lai cuối cùng của Ethereum là gì? Cộng đồng Ethereum từng lo lắng về việc L2 làm xói mòn giá trị của L1 và phá vỡ khả năng kết hợp toàn cầu. Bài viết phân tích sự điều chỉnh mối quan hệ giữa L1 và L2 trong bối cảnh mở rộng quy mô của Ethereum. Định vị mới của L2: Với việc L1 tự nâng cao khả năng xử lý (tăng Gas Limit, zkEVM...), vai trò chính của L2 không còn đơn thuần là cung cấp không gian giao dịch rẻ hơn. Thay vào đó, L2 sẽ chuyển sang cung cấp các chức năng khác biệt mà L1 khó đáp ứng thống nhất, như tối ưu hóa ứng dụng cụ thể, tính riêng tư và mô hình quản trị linh hoạt. L2 sẽ trở thành một dải phổ liên tục từ các Rollup kế thừa bảo mật tối đa của Ethereum đến các môi trường thực thi độc lập hơn. Tương tác & Kết hợp lại: Sự phân mảnh giữa các L2 gây ra vấn đề về thanh khoản và trải nghiệm người dùng. Giải pháp nằm ở việc cải thiện khả năng tương tác, không chỉ là "một nút chuyển chuỗi", mà là làm cho các trạng thái giữa các môi trường thực thi có thể tin cậy lẫn nhau nhanh hơn, thông qua các khung công việc Intent, Lớp Tương tác Ethereum (EIL) và việc rút ngắn đáng kể thời gian xác nhận cuối cùng (finality). L1 như "Rollup của chính nó": Với sự phát triển của hệ thống chứng minh (như zkEVM), trong tương lai, các trình xác thực L1 có thể xác minh trạng thái thông qua bằng chứng mật mã thay vì thực thi lại mọi giao dịch. Điều này chia sẻ kiến trúc "thực thi-tách biệt-xác minh" với Rollup, làm mờ ranh giới truyền thống giữa L1 và L2. Các L2 tiên tiến (Native Rollup) có thể kế thừa trực tiếp hơn khả năng xác minh từ giao thức L1. Tóm lại, tương lai của Ethereum không phải là L1 thay thế L2 hay ngược lại, mà là một hệ sinh thái gồm nhiều môi trường thực thi (L2) đa dạng về chức năng và hiệu suất, nhưng có thể chia sẻ nền tảng bảo mật, thanh khoản và quan hệ trạng thái, từ đó tái tạo lại trải nghiệm "một chuỗi" thống nhất cho người dùng.

marsbit16 phút trước

L2 'Tái hiệu chuẩn': Khi L1 Trở Thành Rollup Của Chính Mình, Cục Diện Cuối Cùng Của Ethereum Là Gì?

marsbit16 phút trước

Grayscale Nộp Đơn Đăng Ký ETF Worldcoin Đầu Tiên Lên SEC Dưới Mã Ticker GWLD

Công ty Grayscale Investments đã nộp hồ sơ đăng ký Biểu mẫu S-1 lên Ủy ban Chứng khoán và Giao dịch Hoa Kỳ (SEC) để ra mắt một quỹ ETF tiền mã hóa mới, dự kiến niêm yết trên sàn Nasdaq với mã GWLD. Quỹ này nhằm cung cấp cho nhà đầu tư Mỹ cách tiếp cận được quy định đối với Worldcoin (WLD), đặc biệt khi công dân Mỹ không đủ điều kiện nhận tài trợ người dùng trực tiếp từ Worldcoin. Thông báo này đã giúp giá WLD tăng hơn 8%, dù token trước đó đã chạm mức thấp kỷ lục. Hồ sơ cũng nêu bật các vấn đề về tokenomics, chẳng hạn như 100 địa chỉ ví hàng đầu nắm giữ ~90% nguồn cung lưu hành và việc mở khóa token liên tục cho đến năm 2028 có thể gây áp lực bán. Ngoài ra, hệ sinh thái Worldcoin với công nghệ quét mống mắt (Orbs) đối mặt với những thách thức pháp lý về thu thập dữ liệu sinh trắc học ở nhiều khu vực pháp lý. Dù việc niêm yết có thể bị trì hoãn đến cuối năm 2026, Grayscale vẫn đang mở rộng danh mục sản phẩm đầu tư tiền mã hóa có quy định, cho thấy nỗ lực thiết lập vị thế trên thị trường ETF non trẻ trước khi các tổ chức khác tham gia.

TheNewsCrypto30 phút trước

Grayscale Nộp Đơn Đăng Ký ETF Worldcoin Đầu Tiên Lên SEC Dưới Mã Ticker GWLD

TheNewsCrypto30 phút trước

Những mảnh vỡ vĩnh cửu của tiền bạc: Thanh toán bên thứ ba không có tính nguyên tắc đầu tiên

**Tóm tắt: Mảnh vỡ vĩnh cửu của tiền tệ: Ngành thanh toán bên thứ ba không có 'tính nguyên lý đầu tiên'** Ngành thanh toán đang ở một thời điểm then chốt. Stripe, sau khi bỏ lỡ cơ hội IPO trong đại dịch, đang cố gắng mua lại PayPal để bổ sung năng lực thị trường C2C, trong một nỗ lực nhằm kích thích định giá và kể một câu chuyện mới trước khi lên sàn. Tuy nhiên, cuộc chiến trong ngành thanh toán bên thứ ba giống như một trận chiến tiêu hao vĩnh viễn, khó có thể loại bỏ các công ty nhỏ hơn do hai đặc điểm cốt lõi: sự phân mảnh theo quốc gia, ngành và khách hàng; và bản chất là sản phẩm phụ của hệ thống ngân hàng. Stripe đã thử mở rộng từ thị trường nhà phát triển (D) sang doanh nghiệp (B) và người tiêu dùng (C), đồng thời đặt cược vào tương lai thông qua ổn định tiền (stablecoin) và thanh toán tự động (Agentic Payment). Nhưng stablecoin chưa phải là xu hướng thanh toán phổ biến, và các Agent vẫn cần một lối vào hệ thống truyền thống. Giá trị của Stripe giống như một sản phẩm quyền chọn, phụ thuộc vào mức độ thành công của những câu chuyện này. Cơ hội thực sự trong làn sóng stablecoin và Agent có lẽ không nằm ở việc phát hành stablecoin, mà nằm ở hệ thống thanh toán bù trừ (clearing network) hiệu quả cao. Các công ty như Stripe (với Tempo) và Circle (với Arc) đang xây dựng các blockchain và stablecoin của riêng họ, với mục tiêu cuối cùng là thiết lập các mạng lưới thanh toán bù trừ có thể thu hút dòng tiền và giữ lại lợi nhuận, phần nào thoát khỏi sự phụ thuộc hoàn toàn vào hệ thống ngân hàng thương mại truyền thống. Đây có thể là con đường để vượt qua cấu trúc phân mảnh và phụ thuộc vốn có của ngành thanh toán.

marsbit39 phút trước

Những mảnh vỡ vĩnh cửu của tiền bạc: Thanh toán bên thứ ba không có tính nguyên tắc đầu tiên

marsbit39 phút trước

Cuộc Chạy Đua Thông Qua Dự Luật Clarity: Con Đường Thoả Hiệp Hai Đảng Ở Mỹ Gai Góc

Đạo luật Clarity về cấu trúc thị trường tiền mã hóa tại Mỹ đang phải đối mặt với một chặng đường lập pháp đầy chông gai, nơi sự thỏa hiệp giữa hai đảng trở thành yếu tố then chốt cho sự sống còn của nó. Hành trình của dự luật bắt đầu với sự gián đoạn vào tháng 1, khi CEO Coinbase Brian Armstrong làm đảo lộn một thỏa thuận lưỡng đảng tại Ủy ban Ngân hàng Thượng viện. Phải đến bốn tháng sau, nhờ một thỏa hiệp về vấn đề "lợi nhuận" giữa Thượng nghị sĩ Angela Alsobrooks (Dân chủ) và Thom Tillis (Cộng hòa), dự luật mới được đưa vào chương trình nghị sự. Tuy nhiên, các điều khoản về đạo đức lại trở thành điều kiện bắt buộc đối với phe Dân chủ, khiến dự luật cuối cùng được thông qua tại Ủy ban Nông nghiệp Thượng viện chỉ với sự ủng hộ theo đường lối đảng, không có phiếu nào từ phe Dân chủ. Các tranh cãi tiếp tục bùng phát vào tháng 7. Ngoài vấn đề đạo đức, các bất đồng về quy định "lợi nhuận" đã khiến một số nghị sĩ Cộng hòa đứng về phía các ngân hàng lớn, trong khi các cơ quan thực thi pháp luật phản đối mạnh mẽ các điều khoản bảo vệ nhà phát triển. Mối quan tâm chính vẫn là rủi ro tài chính bất hợp pháp và bảo vệ người tiêu dùng. Dù vậy, động lực cho dự luật vẫn đang hình thành. Các cuộc thảo luận giữa các nghị sĩ và quan chức Nhà Trắng đang được tiến hành để tìm kiếm ngôn ngữ thỏa hiệp về đạo đức. Cộng đồng kỳ vọng một bản dự thảo hòa giải giữa hai ủy ban của Thượng viện sẽ sớm được công bố. Tuy nhiên, vẫn còn nhiều nghi ngờ về khả năng đạt được sự ủng hộ đủ rộng rãi từ cả hai đảng. Mục tiêu ngắn hạn của cộng đồng tiền mã hóa có thể là một hành động biểu tượng tại Thượng viện trước kỳ nghỉ hè tháng 8, hoặc hướng tới việc thông qua dự luật tại cả hai viện và được ký thành luật vào năm 2026. Con đường phía trước vẫn còn nhiều trở ngại, nhưng quá trình vận động hành lang kiên trì, giành từng phiếu bầu và từng nghị sĩ, chính là chiến thuật mà ngành công nghiệp này cần theo đuổi.

Foresight News1 giờ trước

Cuộc Chạy Đua Thông Qua Dự Luật Clarity: Con Đường Thoả Hiệp Hai Đảng Ở Mỹ Gai Góc

Foresight News1 giờ trước

Giao dịch

Giao ngay
活动图片