
KelpDAO has announced plans to migrate from LayerZero to Chainlink's CCIP following a devastating $293 million exploit that drained approximately 116,500 rsETH from their cross-chain bridge on April 18th. According to AMBCrypto, KelpDAO blamed LayerZero's infrastructure for the attack, claiming that LayerZero's own infrastructure was exploited, resulting in $300 million losses across the DeFi ecosystem. The attack occurred when attackers compromised LayerZero's verifier network's RPC nodes, allowing fake transactions to get approved. KelpDAO used independent data from major on-chain investigators including SEAL 911 and Chainalysis to support their claims that LayerZero approved the exploit configuration and failed to warn relevant parties of potential risks.
LayerZero CEO and co-founder Bryan Pellegrino strongly refuted KelpDAO's claims, calling most allegations false in his official X account. Pellegrino claimed that rsETH was originally configured to use the default LayerZero configuration of multiDVN setup of LayerZero and Google Labs, but Kelp manually migrated to a 1/1 configuration. He added that rsETH accounted for nearly 100% of the volume on the 1/1 configuration and used multiple screenshots to support his defense. However, Kelp argued that LayerZero's termination of the 1.1 DVN configuration after the exploit confirms widespread usage and that it changed only after the attack. The compromise allowed fake transactions to get approved, with Kelp claiming that two additional forged transactions totaling $100 million were signed and processed by LayerZero Labs DVN before being blocked by Kelp after contract pausing.
The KelpDAO incident has highlighted critical security vulnerabilities across the DeFi ecosystem. About 47% of LayerZero OApp contracts used the 1-1 DVN verification model, with more than 120 protocols employing this configuration. According to AMBCrypto, about 90% of messages were verified by just one or two DVNs, creating significant centralization risks. The attack has raised broader questions about DVN centralization and shared control points, using default configurations without proper verification, and lack of timely attack monitoring. KelpDAO emphasized that it was the first to detect the issue and halt the contracts, while LayerZero later confirmed that North Korean Lazarus Group may be linked to the attack. Some of the funds were successfully blocked, with 30,766 ETH worth $71 million frozen by the Arbitrum network, though 34,500 ETH worth $80 million was routed out via THORChain before being laundered.
The migration to Chainlink's CCIP represents a significant strategic shift for cross-chain security in the DeFi ecosystem. As reported by AMBCrypto, Chainlink welcomed the developments, promising to work with Kelp and others to improve the cross-chain security of rsETH. Chainlink's Community Liaison Zach Rynes blamed LayerZero for over-ignoring the protocol's infrastructural failure, while Kelp's decision to switch to Chainlink is a major blow to LayerZero as it signals dwindling confidence in the network. Chainlink's CCIP uses multiple independent validators instead of a single verifier, addressing the security concerns that led to the current exploit. The migration suggests that market players no longer trust LayerZero's infrastructure and capabilities, marking a significant shift in cross-chain bridge adoption patterns. KelpDAO emphasized their approach going forward: "Going forward, our approach is to leverage battle-hardened, time-tested infrastructure, minimize trust in all dependencies."