Logo
My Crypto News AI

LayerZero Admits Design Flaw After $292M Kelp Hack; $1.4B in Assets Flee to Rival

LayerZero Labs publicly admitted in May 2026 that it made a fundamental design error by allowing its Decentralized Verifier Network (DVN) to secure high-value bridge assets using a single-verifier configuration, a flaw that directly enabled the April 18 theft of 116,500 rsETH tokens worth approximately $292 million from Kelp DAO. The admission reversed weeks of blame-shifting and triggered a mass exodus of protocol assets to competing bridge infrastructure, signaling a structural loss of confidence in LayerZero's cross-chain security model.

What Actually Happened in the Kelp DAO Attack?

The April 18 exploit was not a traditional smart contract vulnerability. Instead, attackers attributed by TRM Labs to North Korea's Lazarus Group executed an off-chain infrastructure attack targeting LayerZero's DVN, the network responsible for verifying that cross-chain messages are legitimate before a bridge releases funds. In Kelp's configuration, a single DVN node controlled whether funds moved across chains. The attackers obtained the list of remote procedure call (RPC) endpoints that the DVN node used to read blockchain data, then compromised two of LayerZero's internal RPC nodes and launched a distributed denial-of-service (DDoS) attack against external backup providers. This forced the DVN to rely on the poisoned infrastructure, which fed it fabricated cross-chain messages. The DVN, seeing what appeared to be valid instructions, signed off on the transaction. Kelp's bridge released 116,500 rsETH tokens to the attacker before the protocol's emergency pause multisig could react, which occurred 46 minutes after the drain began.

Two follow-up attempts, each carrying instructions to drain another 40,000 rsETH tokens worth roughly $100 million each, both reverted after the pause took effect. The attack mechanism reveals a critical gap in bridge security disclosure: DVN configuration is invisible to users. A protocol secured by a single verifier and one secured by multiple independent verifiers both appear in public documentation as "using LayerZero," with no standardized disclosure or public registry allowing depositors to check the actual fault tolerance of a bridge before committing capital.

Why Did LayerZero's Admission Matter So Much?

For three weeks following the exploit, LayerZero pointed to Kelp DAO's configuration choices as the root cause. Kelp countered by publishing evidence that LayerZero personnel had reviewed and approved the single-verifier setup before deployment, creating a factual dispute with significant liability implications. LayerZero's May 9 statement reversed this position, stating: "We made a mistake by allowing our DVN to act as a 1/1 DVN for high-value transactions. We didn't police what our DVN was securing, which created a risk we simply didn't see".

Data analysis made the original framing indefensible. A Dune Analytics query published by The Block showed that as of early May 2026, approximately 47 percent of active LayerZero OApp (omnichain application) contracts were using the same default 1-of-1 DVN setup that enabled the Kelp drain. This meant Kelp was not making an unusual or negligent configuration error; it was doing what nearly half of LayerZero's customer base was doing. Following the admission, LayerZero announced that all default pathways are moving toward 5-of-5 or minimum 3-of-3 verification setups where possible and banned new high-value deployments from using the 1-of-1 model, though whether existing deployed contracts will be forced to migrate or merely encouraged to do so remains unclear.

How Are Protocols Responding to Restore Trust?

The hack did not stay contained to the bridge layer. Because the attacker deposited nearly 90,000 fraudulently minted rsETH tokens into Aave as collateral and borrowed roughly $190 million in real ETH and other assets, the exploit became Aave's governance problem as well. Aave's governance response, published May 7, 2026, overhauled how new assets qualify for use as collateral on the protocol. The new framework requires that every asset seeking listing be evaluated not just on price volatility, the traditional metric for collateral risk, but also on cybersecurity architecture, interoperability dependencies, and underlying technical structure.

This means a liquid restaking token backed by a LayerZero bridge now faces an explicit assessment of whether its bridge security model meets Aave's standards. Aave also committed to publishing a minimum-standards playbook for issuers seeking to list, signaling that rsETH's path to collateral status moved too fast relative to the due diligence required. The governance action reads as an implicit admission that protocols had been moving faster than their security infrastructure could support.

What Triggered the $1.4 Billion Migration Away from LayerZero?

Kelp DAO's decision to move rsETH from LayerZero to Chainlink's Cross-Chain Interoperability Protocol (CCIP) was announced in early May 2026 and framed as a straightforward security upgrade, with the protocol switching from LayerZero's OFT (omnichain fungible token) standard to Chainlink's Cross-Chain Token standard. The language was measured, but the message was unmistakable: LayerZero's architecture was no longer trusted.

Solv Protocol's announcement on May 7 was blunter. Solv told CoinDesk it was migrating $700 million in SolvBTC and xSolvBTC infrastructure, tokenized bitcoin assets used across decentralized finance (DeFi) and the BTCfi market, because recent incidents had convinced the team to upgrade the infrastructure used to move assets between blockchains. The migration covers four networks currently using LayerZero bridges: Corn, Berachain, Rootstock, and TAC. LayerZero bridge support for SolvBTC and xSolvBTC on those networks will be deprecated.

Together, Kelp and Solv represent more than $1.4 billion in protocol asset value migrating toward Chainlink CCIP in a matter of weeks. For context, LayerZero's total locked value across its bridge infrastructure sits in the range of $8 billion to $12 billion. Losing $1.4 billion is not existential, but it is the kind of signal that accelerates a broader re-evaluation, especially when the protocols leaving are the ones whose users just watched a $292 million drain happen.

How Do Different Bridge Architectures Compare?

  • LayerZero's DVN Model: Uses a Decentralized Verifier Network where configuration can default to a single node controlling fund releases, creating a single point of failure if that node is compromised or manipulated through infrastructure attacks.
  • Chainlink's CCIP Model: Employs independent node operators, separate source and destination chain validation, and a Risk Management Network that monitors for anomalous cross-chain activity in real time, distributing trust across multiple independent layers.
  • Trust Distribution: The migration reflects a specific architectural argument: a system with multiple independent verification layers is structurally harder to compromise than one where a single node controls whether funds move across chains.

Whether Chainlink's CCIP is hack-proof is a different question; no bridge architecture has been. But the migration reflects a clear preference for systems that distribute verification responsibility rather than concentrating it.

What Should Protocol Teams and Users Know Going Forward?

The Kelp DAO exploit and its aftermath expose a critical gap in how cross-chain infrastructure is disclosed and evaluated. DVN configuration is invisible to end users and often invisible to protocols depositing capital. A protocol using a single-verifier bridge and one using a five-of-nine verifier bridge both appear in public documentation as "using LayerZero," with no standardized way for depositors or counterparty protocols to assess the actual security model before committing assets.

The $1.4 billion migration signals that protocols are now treating bridge security architecture as a primary selection criterion, not a secondary consideration. Aave's governance response indicates that decentralized finance platforms are beginning to treat interoperability dependencies as a core component of collateral risk assessment, not an afterthought. And LayerZero's admission, while late, establishes a precedent that infrastructure providers bear responsibility for the default configurations they ship to customers, even when those customers have the technical ability to override them.

The broader implication is structural: cross-chain bridge security is no longer a technical problem that can be solved by a single vendor or architecture. It is now a governance and disclosure problem that requires transparency, standardized risk assessment frameworks, and protocols willing to migrate away from infrastructure that fails to meet those standards.

" }