Cross-chain bridge exploits have drained $750 million from DeFi protocols in the first five months of 2026, according to PeckShield data, with North Korea's Lazarus Group attributed to 76% of total stolen value via just two operations. The crisis peaked in April when the $292 million KelpDAO expl...
"North Korea stole 76% of all crypto hack value in 2026 — with just two attacks." — Ari Redbord, Global Head of Policy, TRM Labs
Cross-chain bridge exploits have drained $750 million from DeFi protocols in the first five months of 2026, according to PeckShield data, with North Korea's Lazarus Group attributed to 76% of total stolen value via just two operations. The crisis peaked in April when the $292 million KelpDAO exploit and $285 million Drift Protocol attack produced the worst-hacked month on record. Eight additional bridge incidents in May added $328.6 million to the cumulative toll.
The damage has triggered an industry-wide security migration. Approximately $4 billion in cross-chain assets has moved from LayerZero to Chainlink's Cross-Chain Interoperability Protocol (CCIP) since April 18. Protocols including KelpDAO, Lombard Finance, Kraken, and Solv Protocol have abandoned single-verifier bridge architectures. LayerZero has responded by mandating minimum 3-of-3 DVN configurations and raising its multisig threshold from 3-of-5 to 7-of-10.
The pattern is structural: bridges remain DeFi's largest single point of failure, custodying $21.94 billion in TVL across hundreds of chains while relying on verification models that state-sponsored attackers can compromise.
| Date | Protocol | Amount | Attack Vector | |------|----------|--------|--------------| | Jan 31 | CrossCurve | $3M | Spoofed cross-chain messages via missing validation check | | Mar 11 | Transit Finance | $1.88M | Cross-chain aggregation exploit | | Apr 1 | Drift Protocol | $285M | Social engineering + fake collateral token | | Apr 18 | KelpDAO | $292M | RPC compromise + 1-of-1 DVN bypass | | May 13 | Transit Finance | $1.88M | Repeated aggregation exploit | | May 18 | Verus-Ethereum | $11.58M | Verification flaw in reserve confirmation | | May 22 | IoTeX Bridge | $4.4M | Cross-chain infrastructure exploit | | Various | 8 additional incidents | ~$150M | Multiple vectors |
Total 2026 through May 24: Approximately $750 million in confirmed losses across bridge protocols, per PeckShield tracking.
On April 18, 2026, attackers linked to North Korea's TraderTraitor group stole 116,500 rsETH ($292 million) from KelpDAO's LayerZero-powered bridge. The attack exploited a configuration flaw rather than a smart contract vulnerability.
Technical mechanism:
Configuration dispute: KelpDAO operated with a single Decentralized Verifier Network (DVN). LayerZero Labs stated it recommended multi-DVN setups; KelpDAO countered that LayerZero had "approved" the 1-of-1 configuration. On May 9, LayerZero CEO Bryan Pellegrino acknowledged the company "made a mistake" in allowing the setup.
Recovery: The Arbitrum Security Council froze over 30,000 ETH of attacker funds. A coalition branded "DeFi United" — including Aave, Mantle, Lido DAO, EtherFi, and LayerZero — raised over $300 million in commitments to restore rsETH's 1:1 backing. The recovery plan involves staged ETH deposits and governance-approved liquidations across Aave and Compound markets.
On April 1, 2026, Drift Protocol — Solana's largest decentralized perpetual futures exchange — lost $285 million in 12 minutes. The attack was the culmination of six months of social engineering by North Korean operatives attributed with medium confidence to UNC4736.
Attack methodology:
On-chain staging began March 11 with a 10 ETH withdrawal from Tornado Cash. The actual drain occurred in 12 minutes on April 1. Stolen proceeds were converted to USDC, bridged to Ethereum, swapped to ETH, and have not moved since — consistent with DPRK's documented patient, multi-year cashout pattern.
According to Bloomberg, this represents the largest DeFi exploit of 2026 and the second-largest in Solana's history behind the $326 million Wormhole hack of 2022.
PeckShield tracked eight bridge exploits in May 2026 totaling $328.6 million in losses. The most notable:
Verus-Ethereum Bridge (May 18): Attackers drained $11.58 million (103.6 tBTC, 1,625 ETH, 147,000 USDC) by exploiting a verification flaw that allowed asset release on Ethereum without confirming backing on the Verus chain. The attacker's wallet was traced to a Tornado Cash seed.
Resolution: On May 22, the Verus team negotiated a bounty deal. The attacker returned 4,052.4 ETH (~$8.5 million) and retained 1,350 ETH (~$2.8 million) as a bounty. The deal included commitments to halt investigations and avoid legal action — a pragmatic recovery model increasingly common in DeFi.
IoTeX Bridge: A $4.4 million exploit prompted a 10% bounty offer, with negotiations ongoing as of May 23.
According to TRM Labs data published in May 2026:
Laundering approaches diverged:
The initial funding for the KelpDAO exploit is traceable to a 2018 Bitcoin wallet controlled by Wu Huihui, a Chinese crypto broker indicted in 2023 for laundering Lazarus proceeds, according to Chainalysis.
The KelpDAO exploit catalyzed the largest interoperability infrastructure migration in DeFi history. According to Chainlink and CoinDesk reporting:
Protocols that migrated from LayerZero to CCIP: | Protocol | Assets Moved | Date | |----------|-------------|------| | KelpDAO | rsETH (full migration) | Late April | | Lombard Finance | ~$1B+ | May 2026 | | Kraken | kBTC + future wraps | May 14 | | Solv Protocol | ~$500M | May 2026 | | Re Protocol | ~$500M | May 2026 |
CCIP's security model differs fundamentally from LayerZero's configurable approach. CCIP enforces a minimum of 16 node operators for verification consensus. Current operators include Coinbase, Kraken, Lido, Maple Finance, and World Liberty Financial.
LayerZero's remediation (announced May 2026):
Emerging alternatives:
Structural limitations remain: Restaking mechanisms proposed as bridge security lack slashing implementation. ZK proofs remain computationally expensive for high-throughput paths. Intent-based systems introduce solver centralization risk.
Bridge exploits have produced more than $2.8 billion in cumulative losses since 2022, representing approximately 40% of all value hacked in Web3:
| Year | Notable Bridge Hacks | Estimated Losses | |------|---------------------|-----------------| | 2022 | Ronin ($625M), Wormhole ($320M), Nomad ($190M) | ~$1.4B | | 2023 | Multichain ($130M+), various | ~$400M | | 2024 | Orbit Chain ($80M), various | ~$300M | | 2025 | Multiple incidents | ~$1.1B | | 2026 (through May) | KelpDAO ($292M), Drift ($285M), 8 May incidents | ~$750M |
Bridge TVL stood at $21.94 billion as of March 2026. The attack surface is expanding: a bridge custodying wrapped assets across 20+ chains becomes a single point of failure for every downstream protocol accepting those wrapped tokens.
The 2026 bridge exploit wave confirms a structural thesis: cross-chain bridges concentrate more value in fewer points of failure than any other DeFi primitive. The $750 million in year-to-date losses represents not a failure of cryptography but of configuration, social engineering, and verification architecture.
The industry response — a rapid $4 billion migration toward higher-redundancy verification systems — suggests the market is repricing bridge security risk in real time. LayerZero's admission of error and mandatory migration to multi-DVN configurations represents an architectural concession that single-verifier models cannot withstand nation-state adversaries.
The unresolved question is whether any verification architecture can resist attackers willing to spend six months socially engineering multisig holders (Drift) or compromising RPC infrastructure (KelpDAO). Zero-knowledge bridges and intent-based systems eliminate some attack surfaces but introduce others. The $21.94 billion in bridge TVL remains the largest concentrated target in decentralized finance.