EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

The $15 billion migration: Why the cryptocurrency industry collectively shifted from LayerZero to Ch

2026-08-21 00:18:04
Bookmark

Kelp DAO Cross-Chain Bridge Attack: A crisis that rewrites the landscape of DeFi's infrastructure

The Kelp DAO Cross-Chain Bridge Attack not only caused US$292 million in damage, but also triggered the largest infrastructure migration in DeFi history. Data suggests that LayerZero may never be able to recover its lost ground.


Summary

publicly announced that the total value of assets migrated from LayerZero to Chainlink CCIP has reached nearly US$15 billion, of which BitGo transferred US$7.4 billion in WBTC, Mantle transferred US$2.5 billion in Super Portal, and Lombard transferred more than US$1 billion in bitcoin-backed assets.

On April 18, 2026, the Kelp DAO Cross-Chain Bridge attack stole 116,500 rsETH (worth US$292 million) through forged cross-chain messages using a single validator configuration. The attack was later traced to North Korea's Lazarus Group.

LayerZero's decentralized validator network model allows applications to choose as few as one validator to validate cross-chain messages, while Chainlink CCIP requires at least 16 independent node operators per channel, plus a separate risk management network.

The Wyoming Stability Tokens Commission became the first U.S. public entity to abandon LayerZero, selecting Chainlink CCIP as the exclusive multi-year infrastructure for Frontier Stability Tokens on August 18, 2026.

The market value of LayerZero's ZRO token has dropped to approximately $302 million, well below its all-time high of $7.47, while Nethermind has become the latest infrastructure provider to withdraw from the validator role and join Chainlink as a node operator.


The trigger for the collapse of trust

On April 18, 2026, an attacker forged a cross-chain message on a cross-chain bridge driven by LayerZero and stole 116,500 rsETH. These tokens are worth $292 million. Within hours, stolen assets were deposited as collateral in Aave, lending $190 million in WETH, putting pressure on the lending market and freezing the rsETH pool on Aave V3 and V4. This is the largest DeFi attack this year. But the money is just the beginning of LayerZero's loss.

Four months later, the loss accounts took on a different picture. BitGo, the largest custodian of bitcoin-backed tokens in decentralized finance, has transferred $7.4 billion in WBTC to Chainlink's cross-chain interoperability protocol. Kraken, Mantle, Lombard, Solv Protocol, Virtuals, Re and Wyoming are close behind. The cumulative value of announced migrations is close to $15 billion. Nethermind, one of the operators of LayerZero's own validator network, has ended its role and joined Chainlink as a node operator. The question is no longer whether cross-chain infrastructure will become a winner-take-all market, but whether LayerZero can stop its decline.


Attack details: How trust is broken

The Kelp DAO attack is not a smart contract vulnerability. It was a sophisticated attack on off-chain infrastructure that began six weeks before the theft occurred. On March 6, 2026, the attacker obtained the session key of a developer at LayerZero Labs through social engineering and entered LayerZero's RPC cloud environment. From that location, the attacker contaminated internal RPC nodes and launched DDoS attacks on external nodes, providing false data to a single verifier-the only barrier between the attacker and $292 million.

The key vulnerability lies in configuration choices. Kelp DAO's rsETH Bridge runs on a 1-of-1 DVN setting, which means that the single decentralized verifier network node operated by LayerZero Labs is the only verifier of cross-chain messages. There is no second validator to object. When the attacker broke the link that provided data to the unique verifier, the Ethereum contract freed funds based on a token destruction event that had never occurred on the source chain.

(A tweet quote about Curve Finance suspending LayerZero infrastructure is withheld here)

Mandiant, CrowdStrike and independent security researchers all attributed the attack to North Korea's Lazarus Group, specifically the TraderTraitor cluster. The attackers diverted approximately $175 million in ETH through privacy channels, while Arbitrum successfully froze $71 million in ETH related to the attack.

The loss did not stop at Kelp DAO. The attackers deposited 89,567 rsETH as collateral in Aave V3 and lent $190 million in WETH, assets that are now worthless. Aave was forced to freeze the rsETH market on V3 and V4 to prevent further spread. Liquidation of the attacker's positions took weeks, and Aave completed the final liquidation only after the rsETH price suffered a severe impact. DeFi United launched a recovery plan for affected holders, but the size of secondary losses in the lending market, liquidity pool and derivative positions associated with rsETH has never been fully counted.

A battle of responsibility shirking broke out. LayerZero initially accused Kelp DAO of choosing a highly risky 1-of-1 configuration. Kelp DAO counters that the single validator setting is LayerZero's own default configuration. For three weeks, LayerZero prioritized technical review over clear communication, an approach that its leadership later admitted was lacking. On May 9, LayerZero publicly admitted that it had "made a mistake" by allowing its network of validators to protect high-value assets with risk configurations.

By then, the exodus had begun.


Migrating ledgers

Exchanges are not a wave, but a chain reaction, and each departure makes the next more likely.

Kelp DAO itself took the lead, transferring rsETH to Chainlink CCIP while the dispute with LayerZero was still ongoing. Solv Protocol followed suit in early May, transferring more than $700 million in tokenized Bitcoin infrastructure. Kraken announced on May 14 that Chainlink CCIP will become the exclusive bridging infrastructure for kBTC and all future encapsulated assets. The next day, Lombard relocated more than $1 billion in bitcoin-backed assets, including LBTC and BTC.b.

By mid-May, the total amount of migration had exceeded US$4 billion. Then accelerated.

Virtuals Protocol migrated $700 million in VIRTUAL tokens to enable cross-chain payments for AI agents. Re chose Chainlink CCIP as the exclusive bridge to reUSD, which reached a TVL of US$475 million. Yuzu Money transferred $54.5 million. On July 9, Mantle announced the migration of Super Portal, which it co-developed with Bybit, covering $2.5 billion in MNT tokens. The portal was temporarily closed during the migration window from July 9 to 15.

Then ushered in the biggest escape. On August 4, BitGo announced that it would migrate WBTC (the largest bitcoin-backed token in DeFi) from LayerZero to Chainlink CCIP. The migration involves US$7.4 billion in assets and makes Chainlink CCIP the default infrastructure for all future assets of BitGo. This single announcement almost doubled the cumulative total migration.

On August 18, Wyoming's Stability Coin Council completed the migration, making Frontier stablecoin the United States the first state-issued stablecoin to operate fully on Chainlink CCIP and sign a multi-year contract. Wyoming cited concerns about LayerZero's "disclosure practices and operational safety."

The current cumulative total is close to US$15 billion, involving at least ten naming agreements and one sovereign state entity.


Architectural differences: Why migration is possible

The exodus did not stem from just one attack. It reflects the structural differences in cross-chain security approaches between LayerZero and Chainlink CCIP, which the Kelp DAO attack makes impossible to ignore.

LayerZero V2 adopts a modular architecture with ultra-light nodes and a configurable decentralized validator network as its core. Each application selects its own set of DVNs and specifies the consensus threshold needed to verify cross-chain messages. The design is flexible, but also flexible enough to be deadly, as demonstrated by the Kelp attack. The 1-of-1 setup is inexpensive, but means that a single compromised validator can authorize fraudulent transactions. Costs increase as the number of validators required increases, creating a direct tradeoff between security and cost.

(A tweet quote about the XRP bridging event is hidden here)

Chainlink CCIP takes a different approach. Each cross-chain channel is secured by at least 16 independent node operators operated by Chainlink. An independent risk management network monitors abnormal activity and implements value-based rate limits on each channel, acting as a circuit breaker to limit potential losses even if the main verification layer is breached. The system has passed SOC 2 Type 2 compliance certification and ISO 27001 certification.

The actual difference lies in who bears the responsibility for safety. Under the LayerZero model, each application team must understand the validator economic model, select a trusted DVN, and set thresholds to balance cost and risk. Under CCIP, basic security is built into the protocol itself. As BitGo's statement makes clear, the new settings allow issuers to directly control token contracts, transfer limits, and cross-chain settings without having to manage the validator stack.

LayerZero responded by withdrawing support for 1-of-1 DVN configurations and announcing plans to shift most of the route to a more stringent 5-of-5 validator setting. Whether this will be enough to reverse the migration trend remains an open question. The 5-of-5 model increases the cost of the application and still leaves the choice of validator to each deployer-a responsibility many teams have now decided they no longer want to shoulder.


Mathematical analysis of LayerZero's loss of revenue

This is an undisclosed arithmetic that reveals a story more damaging than any headline.

LayerZero currently charges a 0% agreement fee for cross-chain messages. All message costs go to the DVNs and executors who provide security and deliver messages. Revenue for the LayerZero ecosystem comes from three potential sources: message fees if the fee switch is activated; redemption fees from Stargate; and fees from Zero L1. ZRO's buybacks were provided by funds allocated by the Stargate ecosystem, which went to the LayerZero Foundation.

The fee switch has not been activated yet. The LayerZero Foundation runs an immutable voting contract that enforces an open chain referendum every six months, but token holders have not yet voted to open it.

The following are the results of mathematical calculations. LayerZero is estimated to account for 57% of all cross-chain transaction volume, with cumulative value of more than $100 billion shifting on its trajectory. The wave of Chainlink CCIP migration represents approximately $15 billion in bridging TVLs, assets that have either been migrated or are in the process of migration. This is not transaction volume, but the underlying asset layer, which incurs repeated cross-chain message fees every time they move between chains.

Calculate it on an agreement basis. BitGo's $7.4 billion WBTC is the largest single packaged asset in DeFi. Whenever WBTC moves between Ethereum, Arbitrum, Optimism or any other supported chains, a cross-chain message is generated. Under LayerZero, the message created fees for DVN operators and executors. Under Chainlink CCIP, the same fee flows to Chainlink node operators. Mantle's $2.5 billion MNT tokens regularly bridge between Mantle L2 and the Ethereum main network. Lombard's $1 billion in LBTC and BTC.b moves between Corn, Berachain, Rootstock and other networks. Solv's $700 million SolvBTC bridges four chains. Virtuals '$700 million VIRTUAL token shuttles between Base and other networks to power AI proxy payments.

Add in Kelp DAO's rsETH, Re's $475 million reUSD, Kraken's $330 million kBTC and future encapsulated assets, and Yuzu Money's $54.5 million. This total is not a static number, but a traffic generator. Every dollar spent bridging the TVL generates corresponding message revenue based on how often it moves between chains. Encapsulated Bitcoin products are one of the most frequent bridging users in DeFi due to constant rebalancing and settlement.

The lost fee revenue does not currently belong to LayerZero (because the fee switch is not turned on), but is due to the value of activating it in the future. Each migration narrows the denominator of value that the fee switch may bring. Each departure makes it more difficult for ZRO holders to vote on activation fees, as the remaining transaction basis may not be enough to justify the fees levied on users.

ZRO's market value has dropped to about $302 million, well below its all-time high of $7.47. The top 100 wallets control 87.39% of the supply. An unlock in June 2026 released 25.71 million ZROs (worth approximately US$23 million), adding to selling pressure on already falling tokens. In the past month alone, prices have dropped 38.87%.

A disturbing conclusion: LayerZero's revenue potential was emptied before the revenue engine was launched. Migration not only means a loss of current activities, but also a structural reduction in the future profitability of the agreement.


When the validator leaves

Nethermind's departure on August 19 adds a dimension beyond TVL. Nethermind is not a token project that transfers its assets to different bridges. It is an Ethereum core engineering company that previously ran DVN nodes for LayerZero to verify cross-chain messages as part of the security infrastructure.

Nethermind ended its LayerZero validator role after a so-called "extensive infrastructure review" and joined Chainlink as node operator and strategic technology provider. The company did not release the results of the review and did not point out specific flaws in LayerZero. It did not disclose the cost or timetable for the relocation. But what it does is to move from being part of the LayerZero security layer to being part of Chainlink.

(a tweet quote about the S P Global stablecoin evaluation is omitted here)

The meaning is structural. LayerZero's security model relies on a diverse, high-quality DVN operators. When one of the operators not only leaves, but joins the competing agreement, it sends some signal about the relative attractiveness of operating each network infrastructure. If Nethermind's departure prompts other DVN operators to reassess their positions, LayerZero will face a potential enhancement cycle: Fewer high-quality validators make the network less attractive to applications, which reduces fee revenue for the remaining validators and makes the network less attractive to validators.

LayerZero's shift to a 5-of-5 validator requirement may exacerbate this dynamic. When at least one well-known operator has concluded that the opportunity lies elsewhere, more validators are needed per channel, meaning more operators must be recruited and retained.


State Government Choice

Wyoming's decision deserves separate review because it represents something new in the cross-chain debate: a sovereign entity making infrastructure choices based on operational security rather than token economics.

Frontier Stability Token was launched in January 2026. It is the first fiat backed, fully reserved stability token issued by a U.S. public entity, backed by U.S. dollars and short-term treasury bonds. The committee supports FRNT running on eight networks: Arbitrum, Avalanche, Base, Ethereum, Hedera, Optimism, Polygon and Solana.

The original cross-chain infrastructure was LayerZero. The migration to Chainlink CCIP, completed on August 18, was driven by what the committee called concerns about LayerZero's "disclosure practices and operational security." The contract is exclusive and multi-year. LayerZero has been completely deprecated. The committee said it conducted a comprehensive evaluation of cross-chain providers and concluded that their operational security standards did not meet the requirements of public financial instruments.

FRNT is not a large-cap token. The significance lies in what it stands for: a government-issued financial instrument that chooses one cross-chain protocol over another based on security reviews rather than developer preferences or token incentives. The committee's deployment on eight networks means Chainlink CCIP now provides security for a sovereign stablecoin over a wider network coverage than most private sector tokens.

This is important because government adoption of cross-chain infrastructure creates a lock-in effect that is different from protocol adoption. When BitGo migrates, in theory it can migrate again. But when the state signed a multi-year exclusive contract, it set a precedent that other public entities might follow. If federal stablecoin legislation advances and other states issue their own stablecoin coins, Wyoming's precedent will make Chainlink CCIP the default choice for government-level cross-chain infrastructure.

The LINK token rose about 3% after the announcement, trading at close to $9.67. Markets interpret this as confirmation of a trend rather than an isolated event.


Winner-take-all dynamics in cross-chain infrastructure

Cross-chain messaging has network effects that tend to integrate. The more assets and protocols that use a given infrastructure, the more liquidity flows through its channels, incentivizing more node operators to protect it and making it more attractive to the next migrated protocol. The reverse is true: As assets leave the network, remaining participants bear a disproportionate share of security costs while enjoying fewer network benefits.

LayerZero's position entering 2026 is dominant. It is estimated to account for 57% of all cross-chain transaction volume, peaking at 76% in the second quarter of 2025. More than US$100 billion in cumulative value flows on its trajectory. The Kelp DAO attack did not break LayerZero's code, but it undermined market confidence in LayerZero's security model, especially the principle that applications are responsible for configuring their own verification thresholds.

Chainlink responded by providing a model that is not optional for security and is not down-configurable. 16 node operators per channel, an independent monitoring network, rate limits, and SOC2 compliance. The cost per message is higher. But that's also the model of choice for $15 billion worth of assets now.

The question for the second half of 2026 is whether this will become self-reinforcing. If LayerZero's 5-of-5 validator requirements increase costs to levels comparable to CCIP, the application will face the choice between two similarly priced systems, one of which has accumulated four months of institutional migration momentum. If the fee-switch referendum fails, because the remaining trading basis is no longer sufficient to justify activation, ZRO's value proposition will be further weakened, potentially triggering more departures.

There is also the issue of developer mind occupancy. LayerZero's OFT standard embeds protocol-specific code into token contracts, creating what critics call vendor lock-in. In contrast, Chainlink's cross-chain token standard is designed to allow issuers to retain full ownership of their token contracts and to change providers without redeploying. For teams that have already gone through a forced migration, the criteria to make the next migration easier are clearly attractive.

Cross-chain infrastructure may not be a natural monopoly. But the $15 billion exodus suggests it has a strong winner-take-all character, and the current trajectory favors an agreement that makes security non-negotiable.


Points to pay attention to

LayerZero's next fee-switch referendum: If token holders vote against activation because the remaining trading base is insufficient to justify charging users, it will confirm the argument that revenue is being hollowed out and may accelerate the departure.

DVN operator Retention rate: Whether more validator network operators follow Nethermind to join Chainlink will show whether LayerZero's 5-of-5 requirement can attract enough high-quality validators to function as designed.

Federal stablecoin legislation and state token adoption: If other U.S. states issue stablecoin and follow Wyoming's precedent in choosing Chainlink CCIP, cross-chain infrastructure will become the standard in regulated markets rather than an option at the protocol level.

Kelp DAO Recovery Fund Results: Aave has completed liquidation of the attacker's last rsETH position, but DeFi United's recovery plan for affected holders will test whether the ecosystem can absorb $292 million in losses without creating lasting contagion.

LayerZero Monthly Active Trading Volume: The number of cross-chain messages processed per month (compared to the pre-departure baseline) will be the clearest indicator of whether the migration wave has stabilized or is still accelerating.


Frequently Asked Questions

Is LayerZero still safe after the Kelp DAO attack? LayerZero has removed support for 1-of-1 DVN configurations and is moving to a more stringent 5-of-5 validator setting. The code of the protocol was not compromised during the attack. The vulnerability lies in configuration options that allow a single validator to verify high-value transactions. Applications that use multiple independent validators face a very different risk profile than the original settings of Kelp DAO.

What is the total value of migrating CCIP from LayerZero to Chainlink? As of mid-August 2026, the total publicly announced relocation is approximately US$15 billion. The largest single migration was BitGo's $7.4 billion WBTC, followed by Mantle's $2.5 billion Super Portal and Lombard's $1 billion bitcoin-backed assets. Smaller migrations from Solv, Virtuals, Re, Kraken and Yuzu Money make up the rest.

What is the difference between LayerZero's DVN model and Chainlink CCIP's security mechanism? LayerZero allows each application to choose its own set of decentralized validators network operators and set thresholds that must be agreed upon. Chainlink CCIP requires at least 16 independent node operators per channel and adds an independent risk management network to monitor exceptions and enforce rate limits. The core difference is whether security configuration is the responsibility of the application or the protocol.

Who is behind the Kelp DAO attack? Mandiant, CrowdStrike and independent security researchers attributed the attack to North Korea's Lazarus Group, specifically the TraderTraitor cluster. The intrusion began on March 6, 2026, when the attacker used social engineering to obtain the session key of a developer at LayerZero Labs to gain access to the RPC cloud environment.

Why did Wyoming choose Chainlink CCIP for Frontier Stability Tokens? The Wyoming Stability Tokens Commission cited concerns about LayerZero's disclosure practices and operational security. The committee selected Chainlink CCIP as FRNT's exclusive, multi-year cross-chain infrastructure and completely abandoned LayerZero. FRNT is the first fiat coin-backed stability token issued by a U.S. public entity.

What will happen to LayerZero's revenue if the migration continues? LayerZero currently charges 0% for messaging fees, with all fees flowing to DVN and executors. Revenue potential depends on activating the fee switch through a token holder referendum. Each migration reduces the transaction base that would incur fees if the switch was activated, thereby structurally reducing the future value of ZRO.

Has LayerZero lost its dominant market share in cross-chain messaging? LayerZero will account for an estimated 57% of all cross-chain transaction volume when entering 2026, peaking at 76% in the second quarter of 2025. The $15 billion migration represents a significant reduction in the asset base for generating cross-chain messages through LayerZero, although exact market share data for mid-2026 has not yet been released.

Can the migration trend be reversed? LayerZero moved to the 5-of-5 validator requirement and deprecated unsafe configurations to address specific vulnerabilities that were exploited in the Kelp DAO attack. However, reversing the trend requires switching back on migrated protocols, which involves smart contract upgrades, governance votes and reputational risks for teams that have publicly left on security grounds. Multi-year exclusive contracts, such as the Wyoming contract, make it structurally impossible to reverse for some participants.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP