Following the KelpDAO Hack: $40 Billion in Assets Flee LayerZero, Chainlink Emerges as the Primary 'Beneficiary'

marsbit发布于2026-05-19更新于2026-05-19

文章摘要

Following a major security breach in April where KelpDAO's bridge using LayerZero was attacked for approximately $292 million, a significant shift is underway in the cross-chain infrastructure landscape. An estimated $40 billion in assets is in the process of migrating or has already migrated from LayerZero to Chainlink's Cross-Chain Interoperability Protocol (CCIP). The attack exploited a single-point-of-failure vulnerability due to KelpDAO's 1-of-1 validator configuration within the LayerZero network. Attackers corrupted RPC nodes and used DDoS attacks to force the system to rely on compromised nodes, allowing fraudulent messages. While LayerZero acknowledged a serious error in allowing its validator network to service high-value transactions with such a configuration, the incident highlighted critical security risks. This triggered a rapid migration wave. Starting with KelpDAO on May 6th, several major protocols—including Solv Protocol, Re, Tydro, Kraken, and Lombard—announced switching their cross-chain infrastructure exclusively to Chainlink CCIP. The combined value of these migrations is estimated to be around $40 billion. This movement followed earlier major adoptions by Coinbase (in late 2025) and Circle (in early 2024). Market sentiment reflected this shift, with LINK's price showing relative stability while ZRO (LayerZero's token) declined significantly. Data indicates a net outflow of approximately $20.1 billion from the LayerZero network over 30 days. The migr...

Since the cross-chain bridge of KelpDAO suffered an attack of approximately $292 million in April this year, the security landscape of cross-chain infrastructure has been undergoing a dramatic reshuffle. Statistics show that about $40 billion in assets have completed or are in the process of migrating from LayerZero to Chainlink's Cross-Chain Interoperability Protocol (CCIP).

The attack occurred in the early hours of April 19. The attacker invoked a function of the LayerZero Endpoint V2 contract, triggering the KelpDAO bridging contract to release approximately 116,500 rsETH, worth about $292 million. The protocol's emergency pause mechanism subsequently prevented further losses of around $100 million.

Following the attack, LayerZero issued a statement suggesting that the initial assessment pointed to a highly sophisticated state actor, suspected to be TraderTraitor, a subgroup of the North Korean Lazarus Group.

The core of the attack method involved poisoning the RPC nodes relied upon by the LayerZero decentralized validator network and forcing a system failover to already compromised nodes through a DDoS attack, allowing forged messages to pass through. The central point of controversy is that KelpDAO was using a 1-of-1 single validator configuration at the time, which, once exploited, led to a single point of failure.

LayerZero acknowledged that allowing its official validator network to service high-value transactions with a 1/1 configuration was a serious mistake and announced the cessation of signing messages for single validator setups. KelpDAO pointed out that this configuration had appeared as a default setting in LayerZero's deployment code. Regardless of where the responsibility lies, this attack exposed the vulnerability of cross-chain message verification under specific configurations.

A wave of migrations began shortly after. On May 6, the victim, KelpDAO, took the lead in announcing its abandonment of LayerZero, fully transitioning its rsETH cross-chain facilities to Chainlink CCIP, becoming the first major protocol to leave.

Two days later, the Bitcoin staking protocol Solv Protocol switched the cross-chain infrastructure for its SolvBTC and xSolvBTC, with a total value exceeding $700 million, to CCIP, covering all supported routes.

On the same day, the decentralized reinsurance protocol Re also migrated the cross-chain solution for its deposit token reUSD to CCIP, designating it as the sole cross-chain solution. The non-custodial lending protocol Tydro was also among the first batch to migrate.

On May 14, Kraken announced replacing LayerZero with Chainlink CCIP as the exclusive cross-chain service for its wrapped crypto assets, including wrapped Bitcoin kBTC, covering multiple blockchains such as Ink, Ethereum, and Optimism. On the 16th, Lombard announced abandoning LayerZero, migrating over $1 billion worth of Bitcoin-backed assets to CCIP, adopting a burn-and-mint cross-chain token standard.

According to DefiLlama data, if only counting the current total value locked (TVL) of the main DeFi protocols, the combined scale of these five exceeds $3.4 billion. Factoring in institutional wrapped assets, the overall migration scale reaches approximately $4 billion.

Coinbase had already chosen CCIP as the exclusive interoperability provider for all its wrapped assets as early as December 2025, covering assets like cbBTC, cbETH, cbDOGE, cbLTC, cbADA, and cbXRP, with a total market capitalization of about $7 billion at that time. In January 2024, Circle had also integrated with CCIP to support multi-chain transfers of USDC.

The market's reaction to this shift in trust was directly reflected in token price movements.

According to CoinMarketCap data, LINK has risen 2.73% over the past 30 days, trading at $9.6, with a market cap of $6.98 billion, steadily holding the 16th position in the crypto market. In contrast, ZRO fell 22.63% over the same period, trading at $1.34, with a market cap of $434 million, its ranking slipping to 92nd. LayerZero also faces additional pressure from the unlocking of over 25.71 million ZRO tokens on May 20, worth approximately $34.45 million, accounting for 5.07% of the circulating supply.

According to Dune data, the LayerZero network has seen a net outflow of approximately $2.01 billion over the past 30 days.

Behind the influx of protocols lies the significant difference in security architecture between Chainlink CCIP and LayerZero. Chainlink previously announced in April 2024 that CCIP had entered general availability, supporting blockchains like Arbitrum, Base, BNB Chain, and Ethereum.

Chainlink CCIP deeply integrates with the decentralized oracle network, consisting of multiple independent node operators forming an off-chain consensus layer to observe, verify, and report cross-chain events, supplemented by an independent risk management network providing additional monitoring and protection. Its token transfer mechanism includes built-in rate limiting and timelock upgrades, forming a defense-in-depth security model.

According to Dune data, the cumulative cross-chain token transfer value for Chainlink CCIP has exceeded $2 billion. Among them, the decentralized stablecoin GHO and USDC have the highest shares, reaching 22.4% and 20.2%, respectively, corresponding to amounts of approximately $531 million and $481 million.

In contrast, LayerZero employs a highly modular five-layer architecture, completely separating interfaces, validation, and execution, allowing developers to freely combine decentralized validator networks and configure validation thresholds. This design offers high flexibility but also requires application parties to actively choose and maintain security configurations.

The KelpDAO incident cast a spotlight on the fatal flaw of the single validator configuration. Protocols that had chosen the 1/1 configuration at the time accounted for as much as 47%, prompting many projects to quickly turn to CCIP, which defaults to decentralized validation and offers more comprehensive security controls.

On May 9, LayerZero published a letter of apology, acknowledging mishandling communication over the past three weeks and stating that it should have directly explained the situation earlier rather than prioritizing the completion of a post-mortem analysis report.

LayerZero emphasized that the protocol itself was not affected; rather, the internal RPC used by the LayerZero Labs DVN was poisoned by a data source, while external RPC providers suffered DDoS attacks. It admitted that allowing the Labs DVN to service high-value transactions as a 1/1 configuration was a serious error. The official team will soon release an official post-mortem analysis report in collaboration with external security partners.

相关问答

QWhat triggered the massive migration of approximately $40 billion in assets from LayerZero to Chainlink's CCIP?

AThe migration was triggered by a major security breach on April 19, where the KelpDAO bridge on LayerZero was exploited for roughly $292 million. The attack exposed vulnerabilities, particularly in the single-validator (1-of-1) configuration, leading to a loss of trust and prompting protocols to seek more secure alternatives.

QWhat was the core vulnerability exploited in the KelpDAO attack on LayerZero?

AThe core vulnerability was the use of a single-validator (1-of-1) configuration for message verification. Attackers poisoned the RPC node relied upon by LayerZero's decentralized validator network and conducted a DDoS attack to force the system to fail over to the compromised node, allowing fraudulent messages to be approved.

QWhich major protocols were mentioned as having migrated from LayerZero to Chainlink CCIP following the attack?

AMajor protocols that migrated include KelpDAO (rsETH), Solv Protocol (SolvBTC, xSolvBTC), Re (reUSD), Tydro, Kraken (for wrapped assets like kBTC), and Lombard (for over $1 billion in Bitcoin-backed assets). Coinbase had already selected CCIP in December 2025 for its wrapped assets.

QHow does Chainlink's CCIP security architecture fundamentally differ from LayerZero's approach?

AChainlink CCIP is built on a decentralized oracle network with multiple independent node operators forming an off-chain consensus layer for validating cross-chain events, complemented by a separate Risk Management Network. It features built-in safeguards like rate limits and timelocks. In contrast, LayerZero offers a highly modular architecture that separates interface, verification, and execution, giving developers flexibility to configure their own validator networks and security thresholds, which can introduce risk if not properly managed.

QWhat was the impact of the KelpDAO incident and subsequent migrations on the market value of LINK and ZRO tokens?

AAccording to the article, LINK (Chainlink's token) rose 2.73% over 30 days to $9.6, with a market cap of $6.98 billion. In contrast, ZRO (LayerZero's token) fell 22.63% to $1.34, with its market cap dropping to $434 million and its rank falling to 92nd. LayerZero also faced additional pressure from a token unlock scheduled for May 20.

你可能也喜欢

解读Agent商业、支付与基础设施的真相

作者基于一年来为Agent经济构建基础设施的经验,指出当前Agent商业尚未形成真实、规模化的市场需求,初创公司面临结构性挑战。 文章分析了四个关键场景: 1. **Agent对商户**:目前电商体验中,聊天界面在视觉比价购物上逊于传统界面,商户接入多出于防御性“优化”心态。对话式商业在如外卖等高頻、低决策场景有潜力,但受限于平台开放性和成本。 2. **Agent对API**:开发者现有支付方式(如预付)已能处理低频、小额的API调用成本问题。真正的机会在于服务长尾、小众的供应商市场,但规模有限。 3. **Agent对Agent**:这是长期的愿景,涉及机器间的自动交易与结算,需求真实但当前市场几乎为零,需要专用的基础设施。 4. **Agent对金融**:这是唯一存在现成需求和付费客户的领域。将AI嵌入金融工作流是自然演进,但竞争激烈,老牌机构优势明显。 文章认为,行业巨头因资金充足和战略防御而持续投入,但对初创公司而言,真正的机会并非单纯构建支付层。支付只是更宏大问题——**Agent与人类的协同工作、验证与结算**——的一部分。未来,解决协同问题的公司将主导市场,而非支付服务商。作者团队已转向一个存在真实需求、快速增长且未被充分服务的领域。

marsbit9分钟前

解读Agent商业、支付与基础设施的真相

marsbit9分钟前

Kalshi、MTS 与 a16z 的野望

本文探讨了预测市场在2025年成为投资、加密和媒体领域共同关注焦点的现象,并着重分析了其精神内核的演变及其与风投机构a16z所倡导的“新媒体”愿景的契合。 文章首先回顾了预测市场的思想渊源:从哈耶克关于市场作为分散知识协调机制的观点,到罗宾·汉森设计对数市场评分规则(LMSR)以激励信息真实披露,乃至衍生出的“未来统治”(Futarchy)治理乌托邦构想。 然而,作者指出,a16z在2024-2025年投资估值飙升的预测市场平台Kalshi,为此领域注入了新的精神内涵——“在场感”。在人们与现实世界日益疏离的后现代语境下,预测市场提供了一种通过真金白银下注来介入和“预测”未来的方式,使用户从被动观察者转变为主动的“超级观察者”,从而对抗不确定性与无力感。当足够多人使用并依赖这种媒介时,市场本身将对事件的真实性与重要性获得解释权,这正是a16z构建新媒体帝国的关键拼图。 最后,文章以媒体公司MTS为例,说明a16z的“新媒体”是一种全频段、高烈度的信息工程,旨在“接管时间线”。而Kalshi的核心价值在于,它通过真实的交易数据构建了一种强大的“现实扭曲力场”,其显示的市场概率能深刻影响公众认知与判断,这种赋予私营公司的社会影响力是其获得高估值的根本原因。

链捕手9分钟前

Kalshi、MTS 与 a16z 的野望

链捕手9分钟前

交易

现货
合约

热门文章

如何购买LINK

欢迎来到HTX.com!我们已经让购买ChainLink(LINK)变得简单而便捷。跟随我们的逐步指南,放心开始您的加密货币之旅。第一步:创建您的HTX账户使用您的电子邮件、手机号码注册一个免费账户在HTX上。体验无忧的注册过程并解锁所有平台功能。立即注册第二步:前往买币页面,选择您的支付方式信用卡/借记卡购买:使用您的Visa或Mastercard即时购买ChainLink(LINK)。余额购买:使用您HTX账户余额中的资金进行无缝交易。第三方购买:探索诸如Google Pay或Apple Pay等流行支付方法以增加便利性。C2C购买:在HTX平台上直接与其他用户交易。HTX场外交易台(OTC)购买:为大量交易者提供个性化服务和竞争性汇率。第三步:存储您的ChainLink(LINK)购买完您的ChainLink(LINK)后,将其存储在您的HTX账户钱包中。您也可以通过区块链转账将其发送到其他地方或者用于交易其他加密货币。第四步:交易ChainLink(LINK)在HTX的现货市场轻松交易ChainLink(LINK)。访问您的账户,选择您的交易对,执行您的交易,并实时监控。HTX为初学者和经验丰富的交易者提供了友好的用户体验。

2.0k人学过发布于 2024.03.29更新于 2026.06.02

如何购买LINK

Chainlink深度研究报告:从预言机到上链金融基础设施,LINK的飞轮机制与未来路径

Chainlink 作为去中心化预言机网络的代表项目,自 2017 年上线以来在加密货币行业逐渐形成了不可替代的地位。预言机是连接区块链世界与现实世界数据的关键基础设施,承担着价格数据、跨链通信、现实世界资产(RWA)接入等核心功能。在去中心化金融(DeFi)、跨链生态、资产代币化逐渐成为加密行业主要叙事的背景下,Chainlink 的价值和战略地位日益突出。

1.2k人学过发布于 2025.08.21更新于 2025.08.21

Chainlink深度研究报告:从预言机到上链金融基础设施,LINK的飞轮机制与未来路径

相关讨论

欢迎来到HTX社区。在这里,您可以了解最新的平台发展动态并获得专业的市场意见。以下是用户对LINK(LINK)币价的意见。

活动图片