Kelp DAO Shifts $1.5 Billion to Chainlink CCIP Following Security Breach
Following the April exploit that exposed a critical single-point-of-failure in cross-chain message verification, Kelp DAO has begun migrating approximately $1.5 billion in assets from LayerZero to…

Following the April exploit that exposed a critical single-point-of-failure in cross-chain message verification, Kelp DAO has begun migrating approximately $1.5 billion in assets from LayerZero to Chainlink's Cross-Chain Interoperability Protocol (CCIP), according to Crypto.news. The transition constitutes one of the largest infrastructure reallocations in DeFi to date and reflects a structural reassessment of how bridges architect their verification topology.
Anatomy of the breach
The attack was not a smart contract vulnerability in the conventional sense. The operation began on March 6, 2026 — six weeks before the theft — when an attacker socially engineered a LayerZero Labs developer, harvesting session credentials and pivoting into LayerZero's RPC cloud environment. From that foothold, internal RPC nodes were poisoned while a DDoS layer was directed at external nodes, feeding falsified data to a single verifier. The Ethereum contract then released 116,500 rsETH, valued at $292 million, in response to a token burn that never occurred on the source chain.
The core architectural failure was a configuration decision rather than a code defect. Kelp DAO's rsETH bridge operated under a 1-of-1 DVN setup, meaning a single Decentralized Verifier Network node — operated by LayerZero Labs itself — served as the sole checkpoint between attacker and funds. With no secondary verifier in position to dissent, the compromised data propagated through the messaging layer without challenge. Mandiant, CrowdStrike, and independent researchers have attributed the operation to North Korea's Lazarus Group, specifically the TraderTraitor cluster.
Contagion across lending markets
The stolen assets did not remain static. Approximately 89,567 rsETH were deposited on Aave V3 as collateral, against which the attacker borrowed $190 million in WETH, effectively minting undercollateralized debt across lending markets. Aave responded by freezing rsETH pools on both V3 and V4; final liquidations were completed only after weeks of disruption to the token's price discovery. Around $175 million in ETH was subsequently routed through privacy mixers, while Arbitrum managed to freeze $71 million linked to the exploit. DeFi United announced a recovery framework for affected holders, though the aggregate secondary losses across derivative positions and liquidity pools tied to rsETH have not been publicly reconciled.
A migration wave and its architectural implications
The migration trend extends well beyond Kelp DAO. BitGo, the custodian behind the largest bitcoin-backed token in decentralized finance, has moved $7.4 billion in WBTC to CCIP. Kraken, Mantle, Lombard, Solv Protocol, Virtuals, Re, and the state of Wyoming have announced comparable transitions. The cumulative value of disclosed migrations now approaches $15 billion. Notably, Nethermind — one of LayerZero's own verifier network operators — has concluded its role with the protocol and joined Chainlink as a node operator, a symbolically significant departure given the firm's historical involvement.
The pattern indicates that cross-chain infrastructure is consolidating into a winner-take-all configuration, where the credibility of a verification layer depends less on the number of bridges it serves and more on the independence and distribution of its node operators. From a protocol design standpoint, the lesson is direct: verifier redundancy through N-of-M DVN configurations is transitioning from best practice to baseline expectation. For regulators and institutional custodians, the incident surfaces unresolved questions about disclosure standards for bridge security topology — particularly where a single custodian-operated node governs the integrity of cross-chain messaging for billions in user assets. The long-term question is no longer whether bridges will adopt multi-verifier defaults, but how quickly the rest of the stack — oracles, custody layers, and front-ends — will surface those configurations to end users rather than burying them in technical documentation.