← Back to Webthreepedia
WEBTHREEPEDIA RESEARCH

[COMPARATIVE ANALYSIS] Bridge Exploits Drain $750M in 2026, Trigger Security Overhaul

Zephyra|May 24, 2026|BPF
EXECUTIVE SUMMARY

Cross-chain bridge exploits have drained $750 million from DeFi protocols in the first five months of 2026, according to PeckShield data, with North Korea's Lazarus Group attributed to 76% of total stolen value via just two operations. The crisis peaked in April when the $292 million KelpDAO expl...

"North Korea stole 76% of all crypto hack value in 2026 — with just two attacks." — Ari Redbord, Global Head of Policy, TRM Labs

Executive Summary

Cross-chain bridge exploits have drained $750 million from DeFi protocols in the first five months of 2026, according to PeckShield data, with North Korea's Lazarus Group attributed to 76% of total stolen value via just two operations. The crisis peaked in April when the $292 million KelpDAO exploit and $285 million Drift Protocol attack produced the worst-hacked month on record. Eight additional bridge incidents in May added $328.6 million to the cumulative toll.

The damage has triggered an industry-wide security migration. Approximately $4 billion in cross-chain assets has moved from LayerZero to Chainlink's Cross-Chain Interoperability Protocol (CCIP) since April 18. Protocols including KelpDAO, Lombard Finance, Kraken, and Solv Protocol have abandoned single-verifier bridge architectures. LayerZero has responded by mandating minimum 3-of-3 DVN configurations and raising its multisig threshold from 3-of-5 to 7-of-10.

The pattern is structural: bridges remain DeFi's largest single point of failure, custodying $21.94 billion in TVL across hundreds of chains while relying on verification models that state-sponsored attackers can compromise.

Table of Contents

  1. 2026 Bridge Exploit Timeline
  2. The KelpDAO-LayerZero Incident: Anatomy of a $292M Failure
  3. Drift Protocol: Social Engineering at Scale
  4. May 2026: The Bleeding Continues
  5. North Korea's Dominance of Bridge Attack Value
  6. The Great Migration: LayerZero to Chainlink CCIP
  7. Bridge Security Architecture: What Changed
  8. Historical Context: $2.8B in Cumulative Bridge Losses

2026 Bridge Exploit Timeline

| Date | Protocol | Amount | Attack Vector | |------|----------|--------|--------------| | Jan 31 | CrossCurve | $3M | Spoofed cross-chain messages via missing validation check | | Mar 11 | Transit Finance | $1.88M | Cross-chain aggregation exploit | | Apr 1 | Drift Protocol | $285M | Social engineering + fake collateral token | | Apr 18 | KelpDAO | $292M | RPC compromise + 1-of-1 DVN bypass | | May 13 | Transit Finance | $1.88M | Repeated aggregation exploit | | May 18 | Verus-Ethereum | $11.58M | Verification flaw in reserve confirmation | | May 22 | IoTeX Bridge | $4.4M | Cross-chain infrastructure exploit | | Various | 8 additional incidents | ~$150M | Multiple vectors |

Total 2026 through May 24: Approximately $750 million in confirmed losses across bridge protocols, per PeckShield tracking.

The KelpDAO-LayerZero Incident: Anatomy of a $292M Failure

On April 18, 2026, attackers linked to North Korea's TraderTraitor group stole 116,500 rsETH ($292 million) from KelpDAO's LayerZero-powered bridge. The attack exploited a configuration flaw rather than a smart contract vulnerability.

Technical mechanism:

  1. Attackers compromised two internal RPC nodes operated by LayerZero Labs
  2. External RPC endpoints were DDoSed to force reliance on compromised nodes
  3. The LayerZero Labs DVN — the sole verifier in a 1-of-1 configuration — received poisoned transaction data
  4. The Ethereum contract released 116,500 rsETH based on a phantom token burn on the source chain

Configuration dispute: KelpDAO operated with a single Decentralized Verifier Network (DVN). LayerZero Labs stated it recommended multi-DVN setups; KelpDAO countered that LayerZero had "approved" the 1-of-1 configuration. On May 9, LayerZero CEO Bryan Pellegrino acknowledged the company "made a mistake" in allowing the setup.

Recovery: The Arbitrum Security Council froze over 30,000 ETH of attacker funds. A coalition branded "DeFi United" — including Aave, Mantle, Lido DAO, EtherFi, and LayerZero — raised over $300 million in commitments to restore rsETH's 1:1 backing. The recovery plan involves staged ETH deposits and governance-approved liquidations across Aave and Compound markets.

Drift Protocol: Social Engineering at Scale

On April 1, 2026, Drift Protocol — Solana's largest decentralized perpetual futures exchange — lost $285 million in 12 minutes. The attack was the culmination of six months of social engineering by North Korean operatives attributed with medium confidence to UNC4736.

Attack methodology:

  • Operatives spent months building trust with Drift's multisig signers beginning fall 2025
  • Signers were socially engineered into pre-signing hidden authorizations
  • Attackers exploited a zero-timelock Security Council migration to eliminate defensive delay mechanisms
  • A fabricated token ("CarbonVote Token") was seeded with wash-traded liquidity and accepted by Drift's oracles as legitimate collateral worth hundreds of millions

On-chain staging began March 11 with a 10 ETH withdrawal from Tornado Cash. The actual drain occurred in 12 minutes on April 1. Stolen proceeds were converted to USDC, bridged to Ethereum, swapped to ETH, and have not moved since — consistent with DPRK's documented patient, multi-year cashout pattern.

According to Bloomberg, this represents the largest DeFi exploit of 2026 and the second-largest in Solana's history behind the $326 million Wormhole hack of 2022.

May 2026: The Bleeding Continues

PeckShield tracked eight bridge exploits in May 2026 totaling $328.6 million in losses. The most notable:

Verus-Ethereum Bridge (May 18): Attackers drained $11.58 million (103.6 tBTC, 1,625 ETH, 147,000 USDC) by exploiting a verification flaw that allowed asset release on Ethereum without confirming backing on the Verus chain. The attacker's wallet was traced to a Tornado Cash seed.

Resolution: On May 22, the Verus team negotiated a bounty deal. The attacker returned 4,052.4 ETH (~$8.5 million) and retained 1,350 ETH (~$2.8 million) as a bounty. The deal included commitments to halt investigations and avoid legal action — a pragmatic recovery model increasingly common in DeFi.

IoTeX Bridge: A $4.4 million exploit prompted a 10% bounty offer, with negotiations ongoing as of May 23.

North Korea's Dominance of Bridge Attack Value

According to TRM Labs data published in May 2026:

  • 76% of all crypto hack value in 2026 is attributable to North Korean groups
  • $577 million stolen through just two operations (KelpDAO + Drift)
  • $6 billion+ cumulative crypto theft attributed to DPRK since 2017
  • Two distinct operational groups: TraderTraitor (KelpDAO) and a separate subgroup (Drift)

Laundering approaches diverged:

  • KelpDAO proceeds: Immediately laundered through THORChain and Umbra
  • Drift proceeds: Converted to USDC, bridged to Ethereum, swapped to ETH, dormant since theft

The initial funding for the KelpDAO exploit is traceable to a 2018 Bitcoin wallet controlled by Wu Huihui, a Chinese crypto broker indicted in 2023 for laundering Lazarus proceeds, according to Chainalysis.

The Great Migration: LayerZero to Chainlink CCIP

The KelpDAO exploit catalyzed the largest interoperability infrastructure migration in DeFi history. According to Chainlink and CoinDesk reporting:

  • $4 billion in cross-chain assets moved or committed to Chainlink CCIP since April 18
  • 80,000+ daily active addresses on CCIP, a new record
  • $60-70 billion in cross-chain assets now secured by CCIP

Protocols that migrated from LayerZero to CCIP: | Protocol | Assets Moved | Date | |----------|-------------|------| | KelpDAO | rsETH (full migration) | Late April | | Lombard Finance | ~$1B+ | May 2026 | | Kraken | kBTC + future wraps | May 14 | | Solv Protocol | ~$500M | May 2026 | | Re Protocol | ~$500M | May 2026 |

CCIP's security model differs fundamentally from LayerZero's configurable approach. CCIP enforces a minimum of 16 node operators for verification consensus. Current operators include Coinbase, Kraken, Lido, Maple Finance, and World Liberty Financial.

Bridge Security Architecture: What Changed

LayerZero's remediation (announced May 2026):

  1. All pathways migrating to minimum 5-of-5 DVN consensus (3-of-3 minimum where only 3 DVNs available)
  2. LayerZero Labs DVN will refuse to sign for any 1-of-1 application
  3. Multisig threshold raised from 3-of-5 to 7-of-10 via OneSig
  4. Second DVN client being built in Rust for client diversity
  5. Active outreach to all applications with vulnerable configurations

Emerging alternatives:

  • Zero-knowledge bridges: Wormhole integrating with Boundless (decentralized ZK proof network) for trust-minimized verification. Proving costs have dropped significantly, though computational expense still limits throughput.
  • Intent-based bridging: Eliminates custodial lockup entirely. Specialized solvers compete to fulfill cross-chain transfer "intents" without traditional bridge infrastructure. No asset pools to drain.
  • AI-driven security layers: Intent-Alignment Arbiters monitor cross-chain transaction patterns and can pause suspicious operations in real-time.

Structural limitations remain: Restaking mechanisms proposed as bridge security lack slashing implementation. ZK proofs remain computationally expensive for high-throughput paths. Intent-based systems introduce solver centralization risk.

Historical Context: $2.8B in Cumulative Bridge Losses

Bridge exploits have produced more than $2.8 billion in cumulative losses since 2022, representing approximately 40% of all value hacked in Web3:

| Year | Notable Bridge Hacks | Estimated Losses | |------|---------------------|-----------------| | 2022 | Ronin ($625M), Wormhole ($320M), Nomad ($190M) | ~$1.4B | | 2023 | Multichain ($130M+), various | ~$400M | | 2024 | Orbit Chain ($80M), various | ~$300M | | 2025 | Multiple incidents | ~$1.1B | | 2026 (through May) | KelpDAO ($292M), Drift ($285M), 8 May incidents | ~$750M |

Bridge TVL stood at $21.94 billion as of March 2026. The attack surface is expanding: a bridge custodying wrapped assets across 20+ chains becomes a single point of failure for every downstream protocol accepting those wrapped tokens.

Key Takeaways

  • $750 million lost to bridge exploits in 2026 through May 24, on pace to exceed 2025's $1.1 billion total
  • 76% of 2026 crypto hack value attributable to North Korean state actors via two operations
  • $4 billion in assets migrating from LayerZero to Chainlink CCIP in the largest infrastructure switch in DeFi history
  • Single-verifier architectures (1-of-1 DVN) proved catastrophically insufficient against state-sponsored attackers with capacity to compromise RPC infrastructure
  • Social engineering, not smart contract bugs, enabled the largest individual exploit (Drift, $285M)
  • Negotiated bounties (Verus returning 75% of funds for a $2.8M bounty) remain the primary recovery mechanism for smaller exploits
  • DeFi United coalition demonstrates systemic risk response capability — $300M+ raised to restore rsETH backing — but also reveals the concentration of downstream exposure

Conclusion

The 2026 bridge exploit wave confirms a structural thesis: cross-chain bridges concentrate more value in fewer points of failure than any other DeFi primitive. The $750 million in year-to-date losses represents not a failure of cryptography but of configuration, social engineering, and verification architecture.

The industry response — a rapid $4 billion migration toward higher-redundancy verification systems — suggests the market is repricing bridge security risk in real time. LayerZero's admission of error and mandatory migration to multi-DVN configurations represents an architectural concession that single-verifier models cannot withstand nation-state adversaries.

The unresolved question is whether any verification architecture can resist attackers willing to spend six months socially engineering multisig holders (Drift) or compromising RPC infrastructure (KelpDAO). Zero-knowledge bridges and intent-based systems eliminate some attack surfaces but introduce others. The $21.94 billion in bridge TVL remains the largest concentrated target in decentralized finance.

Sources & References

  1. PeckShield Reports $328.6M Lost to Crypto Bridge Attacks in May — PeckShield tracking of 8 May 2026 bridge incidents
  2. North Korea Stole 76% of All Crypto Hack Value in 2026 — TRM Labs attribution data
  3. Inside the KelpDAO Bridge Exploit — Chainalysis technical breakdown
  4. LayerZero says it 'made a mistake' in $292 Million Kelp exploit — CoinDesk, May 9, 2026
  5. Drift Protocol Hack: $285M Loss — Chainalysis analysis of social engineering attack
  6. $285 Million Drift Hack Traced to Six-Month DPRK Social Engineering Operation — The Hacker News, April 2026
  7. Crypto firms move $4 billion in assets to Chainlink — CoinDesk, May 15, 2026
  8. DeFi United Unveils Technical Plan to Restore rsETH Backing — The Block, April 2026
  9. Verus Hacker Returns $8.5M After Bridge Exploit Deal — Crypto Times, May 22, 2026
  10. Drift DeFi Project on Solana Suffers $285 Million Crypto Exploit — Bloomberg, April 1, 2026
  11. Kelp DAO ditches LayerZero for Chainlink's cross-chain infrastructure — The Block, May 2026
  12. Bridge hacks back in vogue as Verus exploit brings 2026 total to $329M — Protos, May 2026