Cross-chain bridges hold $21.94 billion in total value locked as of March 2026, process over $18.8 billion in monthly transfer volume, and have lost more than $2.8 billion to exploits since 2022. That last figure represents roughly 40% of all value ever stolen in DeFi. The April 2026 Kelp DAO exp...
"We didn't police what our DVN was securing, which created a risk we simply didn't see. We own that." — Bryan Pellegrino, Co-Founder & CEO, LayerZero Labs
Cross-chain bridges hold $21.94 billion in total value locked as of March 2026, process over $18.8 billion in monthly transfer volume, and have lost more than $2.8 billion to exploits since 2022. That last figure represents roughly 40% of all value ever stolen in DeFi. The April 2026 Kelp DAO exploit — $292 million drained from a LayerZero-powered bridge in under an hour — exposed a structural flaw that affected 47% of all active LayerZero application contracts: reliance on a single Decentralized Verifier Network (DVN) as the sole attestation layer.
The aftermath triggered an industry-wide reassessment of bridge verification architecture. LayerZero banned 1-of-1 DVN configurations and migrated defaults to 5-of-5 verification where possible. Chainlink's Cross-Chain Interoperability Protocol (CCIP) posted $18 billion in Q1 2026 transfer volume, a 319% year-over-year increase, built on a dual-verification model that requires independent attestation from both Chainlink node operators and application-designated verifiers. Meanwhile, ERC-7683, the cross-chain intents standard co-developed by Across Protocol and Uniswap, reached 88% of Across's production volume and saw adoption from over 70 projects. The bridge sector is splitting into two architectural camps: verification-centric protocols that strengthen attestation layers, and intent-based systems that eliminate custodial risk by using competitive solvers rather than locked liquidity pools.
Bridges are structurally attractive targets. They custody wrapped assets across multiple chains, creating concentrated pools of liquidity that function as single points of failure for every protocol downstream. According to data compiled by Chainalysis and Yellow Research, cumulative bridge exploit losses exceed $2.8 billion since 2022, accounting for approximately 40% of all funds stolen across DeFi.
The 2026 year-to-date figures underscore the persistence of the problem. Through mid-year, cross-chain bridges lost $340.7 million across 14 exploits, according to Phemex and SpazioCrypto. The Kelp DAO incident alone accounted for 86% of that total.
Historical comparison by year:
| Year | Total DeFi Exploit Losses | Bridge Share (est.) | |------|--------------------------|---------------------| | 2023 | ~$660M | ~$280M | | 2024 | ~$474M | ~$190M | | 2025 | ~$680M | ~$272M | | 2026 (H1) | ~$840M+ | ~$341M |
Sources: Chainalysis, Phemex, altfins, CCN. Bridge share estimates based on reported bridge-specific incidents.
The structural problem is straightforward: bridges hold large pools of locked liquidity and introduce multi-chain logic that is difficult to audit exhaustively. A single vulnerability can drain assets across multiple chains simultaneously.
On April 18, 2026, attackers linked to North Korea's Lazarus Group stole 116,500 rsETH — approximately $292 million, representing 18% of rsETH's entire circulating supply — from KelpDAO's LayerZero-powered bridge. According to Chainalysis's post-incident analysis, this was not a smart contract vulnerability. The attack targeted off-chain infrastructure.
Attack sequence:
KelpDAO's incident response team paused contracts in time to block a second $95 million withdrawal. The Arbitrum Security Council, coordinating with law enforcement, froze over 30,000 ETH of the attacker's downstream funds.
The incident triggered a public dispute between Kelp DAO and LayerZero over responsibility. Kelp DAO stated that the 1-of-1 DVN setup was the default configuration shipped for new deployments at the time of its L2 expansion. LayerZero initially disputed this, but data subsequently showed that 47% of active LayerZero OApp contracts used a 1-of-1 DVN setup before the incident. On May 9, 2026, LayerZero CEO Bryan Pellegrino issued a public acknowledgment, stating: "We didn't police what our DVN was securing, which created a risk we simply didn't see."
Kelp DAO has since migrated its bridge infrastructure to Chainlink CCIP, according to reporting from Unchained Crypto.
LayerZero's post-exploit response included a comprehensive overhaul of its verification defaults:
The migration from 1-of-1 to multi-DVN configurations imposes meaningful costs. Each additional DVN adds latency and gas overhead. For protocols that previously operated with a single verifier for speed, the security upgrade requires re-evaluating the cost-performance tradeoff. According to Autheo's analysis of bridge failure modes, the industry consensus has shifted: "In 2026, one misconfigured trust assumption can unlock nine figures of value and freeze lending markets across multiple chains."
Chainlink's Cross-Chain Interoperability Protocol processed $18 billion in transfer volume during Q1 2026, representing 78% quarter-over-quarter growth and 319% year-over-year growth, according to CoinLaw and Chainlink ecosystem metrics.
CCIP's architecture differs from LayerZero's modular DVN model in a fundamental way: it mandates dual-layer verification by default. Every cross-chain message must be independently attested by:
This design eliminates the possibility of a single compromised component authorizing fraudulent transfers. During the October 2025 AWS outage that disrupted multiple cross-chain providers, CCIP experienced no downtime, demonstrating the practical effect of infrastructure diversity.
The Base-Solana bridge, which went live on December 4, 2025, exemplifies CCIP's institutional deployment model. Chainlink node operators and Coinbase independently authenticate every transfer, creating a two-layer security design. According to Base's blog, early performance showed end-to-end transfer times ranging from under one minute to several minutes, with the bridge processing tens of thousands of messages in its first weeks.
CCIP's total network — including oracle services beyond bridges — now secures over $28 trillion in cumulative transaction value across 17 chains, according to Chainlink's published metrics.
The intent-based model represents a structural alternative to verification-centric bridges. Rather than locking assets in custodial contracts and verifying cross-chain messages, intent protocols allow users to express a desired outcome (e.g., "I want 1,000 USDC on Arbitrum") and competitive solvers race to fill the order from their own inventory.
ERC-7683, the cross-chain intents standard co-developed by Across Protocol and Uniswap, has reached meaningful production adoption:
Across Protocol has processed $35 billion in lifetime volume with zero exploit losses to date, with daily volumes routinely exceeding $50 million. The protocol's security model shifts risk from a shared custodial pool to individual solvers who bear their own capital risk.
The economic implication is significant. Under the intent model, a solver quoting Across orders can simultaneously quote UniswapX orders from the same inventory because the order format is identical under ERC-7683. This converges solver competition across protocols and compresses spreads, according to a May 2026 technical analysis published in Coinmonks.
Wormhole operates a 19-Guardian network requiring 13-of-19 signatures to validate cross-chain messages, connecting 40 blockchains. The protocol has processed over 1 billion messages and $70 billion in cumulative volume. Its Native Token Transfers (NTT) framework, which eliminates wrapped tokens by burning on the source chain and minting natively on the destination, crossed $5 billion in bridged supply in early 2026, per DefiLlama data.
NTT adoption includes Ethena's USDe, Lido's wstETH, and Wormhole's own W token. The framework's two operational modes — hub-and-spoke (lock/mint) and burn-and-mint — offer different security tradeoffs depending on whether a token issuer wants to preserve supply on a central chain or distribute it natively.
Wormhole's Guardian model sits between LayerZero's modular approach and CCIP's oracle-backed verification. The fixed validator set provides consistency but introduces the same concentration risk that plagues smaller multisig bridges if too few Guardians are compromised.
The bridge market is consolidating around three architectural models, each with distinct security and economic properties:
| Model | Representative Protocols | Security Mechanism | TVL/Volume Concentration Risk | |-------|-------------------------|-------------------|------------------------------| | Multi-DVN Verification | LayerZero | Configurable DVN quorum | High (custodial pools) | | Oracle-Backed Dual Verification | Chainlink CCIP | DON + Risk Management Network | Medium (oracle dependency) | | Intent-Based Settlement | Across, UniswapX, deBridge | Competitive solvers, no custodial pools | Low (solver capital at risk) | | Fixed Guardian Set | Wormhole | 13-of-19 multisig | Medium (guardian concentration) |
Monthly bridge volumes tracked by DefiLlama show approximately $18.8 billion flowing across all bridges in recent 30-day windows. Stargate processed $465 million in monthly volume in February 2026. deBridge has accumulated over $20 billion in cumulative lifetime volume across 3 million cross-chain transactions and 550,000 users.
The competitive dynamic is clear: verification-centric protocols are racing to increase attestation requirements, while intent-based protocols are competing on speed, cost, and solver depth. The Kelp DAO exploit accelerated the shift toward mandatory multi-verifier configurations, but it also validated the intent-based thesis that eliminating custodial pools removes the primary attack surface.
The Kelp DAO exploit marked an inflection point for cross-chain bridge security. The industry's response — LayerZero's verification overhaul, CCIP's accelerating adoption, ERC-7683's standardization of intents — reflects a sector that is maturing under pressure rather than collapsing under it. Bridge TVL continues to grow because multi-chain architecture demands it: applications, liquidity, and users are distributed across dozens of networks, and bridges are the connective tissue.
The economic question is whether the security upgrade cycle can outpace the attackers. Bridge exploits dropped from $280 million in 2023 to $190 million in 2024 before rebounding to $341 million in H1 2026, driven almost entirely by a single incident exploiting a configuration flaw that has since been patched industry-wide. The Kelp DAO case was not a novel attack vector — it was a known single-point-of-failure risk that went unenforced. The response has been structural: mandatory multi-verifier attestation, dual-layer oracle verification, and intent-based architectures that remove custodial pools from the equation.
The $21.9 billion locked in bridges is not going to decrease. The relevant metric going forward is not whether bridges will be attacked — they will — but whether the architectural improvements deployed in 2026 reduce the per-incident loss magnitude and frequency. The data from the first half of 2026 suggests that the answer depends entirely on which security model a protocol adopts.