Cross-chain bridge exploits have now drained more than $2.5 billion from crypto protocols since 2021, according to data compiled from DefiLlama and Chainalysis. April 2026 alone accounted for $647 million in total crypto hack losses across 40 incidents — a 1,140% month-over-month increase from Ma...
"We made a mistake by allowing our DVN to act as a 1/1 DVN for high-value transactions. We didn't police what our DVN was securing, which created a risk we simply didn't see. We own that." — LayerZero Labs, public statement (May 9, 2026)
Cross-chain bridge exploits have now drained more than $2.5 billion from crypto protocols since 2021, according to data compiled from DefiLlama and Chainalysis. April 2026 alone accounted for $647 million in total crypto hack losses across 40 incidents — a 1,140% month-over-month increase from March's $52.2 million, per PeckShield. Two bridge-related exploits, the $292 million Kelp DAO drain and the $285 million Drift Protocol theft, comprised 91% of the month's losses. Both attacks are attributed to North Korean state-sponsored hackers.
The fallout is reshaping cross-chain infrastructure market share in real time. Kelp DAO and Solv Protocol have collectively migrated nearly $1 billion in assets away from LayerZero's OFT standard to Chainlink's CCIP. LayerZero's ZRO token fell 3.05% on the news. LayerZero Labs reversed weeks of blaming Kelp DAO and on May 9 conceded it "made a mistake," announcing it will discontinue all 1-of-1 DVN configurations and mandate a minimum 3-of-3 verifier threshold on every pathway.
The episode exposes the structural fragility of cross-chain verification networks and raises questions about whether the "modular security" model — in which application developers choose their own verification parameters — is fit for purpose when billions of dollars in wrapped assets traverse these systems daily.
On April 18, 2026, attackers drained 116,500 rsETH (restaked ether) from Kelp DAO's LayerZero-powered bridge, worth approximately $292 million at the time of the exploit. According to Chainalysis, the attack targeted off-chain infrastructure rather than smart contract logic. The attackers compromised two RPC nodes used by LayerZero Labs' Decentralized Verifier Network (DVN) and launched a distributed denial-of-service attack against uncompromised nodes, forcing a failover to the poisoned endpoints. The DVN then confirmed transactions that had not actually occurred on the source chain.
The exploit was possible because Kelp's bridge operated on a 1-of-1 DVN configuration — meaning only a single verifier network, operated by LayerZero Labs itself, needed to approve cross-chain transfers. This architecture created a single point of failure.
Because the bridge held reserves backing rsETH across more than 20 networks, the loss immediately raised solvency questions for rsETH on layer 2s. Aave, SparkLend, and Fluid froze rsETH markets in response. The ripple effect demonstrated how a single bridge vulnerability can cascade across the DeFi stack.
Three weeks before the Kelp exploit, on April 1, Drift Protocol, a Solana-based decentralized exchange, was drained of $285 million. According to TRM Labs and Chainalysis, the attack was executed by North Korean state-sponsored hackers tracked as UNC4736 (also known as AppleJeus and Citrine Sleet).
The attack was not a conventional exploit. Hackers spent six months infiltrating Drift's operations through in-person social engineering: attending crypto conferences, building genuine professional relationships with Drift contributors, and gradually manipulating Security Council members into signing durable nonce transactions on Solana that transferred admin control to an attacker-controlled address. Once admin access was secured, the attackers whitelisted a fabricated token (CVT) as collateral, deposited 500 million units, and withdrew $285 million in USDC, SOL, and ETH. The entire drain was executed in approximately 12 minutes.
According to The Hacker News, this was the culmination of a multi-country, sustained social engineering operation — a departure from the typical pattern of remote code exploitation.
The weeks following the Kelp exploit produced a public attribution dispute between LayerZero Labs and Kelp DAO that is unusual in its severity.
April 20 — LayerZero's initial position: LayerZero CEO Bryan Pellegrino stated that Kelp originally deployed with LayerZero's default multi-DVN configuration and later manually downgraded to the 1-of-1 verifier setup that was exploited. He noted that "almost 100% of the volume on a 1/1 config was rsETH." LayerZero attributed the attack to North Korea's Lazarus Group.
May 5 — Kelp's rebuttal: Kelp DAO published evidence claiming LayerZero had explicitly approved the 1-of-1 configuration. Kelp also alleged it had to flag the exploit to LayerZero rather than the other way around, raising questions about LayerZero's monitoring capabilities. Pellegrino called Kelp's account "completely untrue."
May 9 — LayerZero's reversal: LayerZero Labs published a statement titled "First things first: an overdue apology," acknowledging it "made a mistake by allowing our DVN to act as a 1/1 DVN for high-value transactions." The statement reversed weeks of public blame directed at Kelp. LayerZero announced two immediate policy changes: (1) its DVN will no longer service 1-of-1 configurations, and (2) all default pathways are being migrated to 5-of-5 where possible and no less than 3-of-3 on any chain where only three DVNs are available.
The dispute highlights a structural ambiguity in LayerZero's "modular security" model: if application developers choose their own verification parameters, who bears liability when those parameters prove insufficient? LayerZero's concession suggests the protocol operator cannot fully delegate security responsibility to downstream deployers — particularly when its own DVN is the sole verifier.
The immediate market consequence is a flight of assets from LayerZero to Chainlink's Cross-Chain Interoperability Protocol (CCIP).
Kelp DAO announced it will migrate all rsETH infrastructure from LayerZero's OFT standard to Chainlink CCIP and adopt the Cross-Chain Token (CCT) standard. The migration directly addresses the single-verifier architecture at the center of the exploit.
Solv Protocol disclosed on May 7 that it is moving more than $700 million in tokenized bitcoin assets (SolvBTC and xSolvBTC) from LayerZero to CCIP, deprecating LayerZero bridge support across Corn, Berachain, Rootstock, and TAC. According to CoinDesk, Solv's internal security review — conducted after the Kelp exploit — convinced the team to upgrade cross-chain infrastructure.
Combined, the two migrations shift nearly $1 billion in assets to Chainlink's infrastructure. Chainlink's CCIP processed more than $18 billion in cross-chain transfer volume during Q1 2026 alone, according to the Chainlink Q1 2026 quarterly review. Other major adopters include Coinbase, which selected CCIP as its exclusive bridge infrastructure for all Coinbase Wrapped Assets (cbBTC, cbETH, cbDOGE, cbLTC, cbADA, cbXRP), and Lido, which upgraded to CCIP for wstETH cross-chain transfers.
LayerZero's ZRO token declined 3.05% following KelpDAO's migration announcement, compounded by a $40.4 million token unlock, according to BanklessTimes.
The Kelp and Drift exploits are not isolated incidents. They represent an acceleration of state-sponsored cryptocurrency theft by the DPRK.
According to TRM Labs data published on April 30, 2026:
The percentage trend is steep: below 10% in 2020–2021, 22% in 2022, 37% in 2023, 39% in 2024, 64% in 2025, and now 76% in the first four months of 2026. The progression suggests DPRK operations are scaling in both sophistication and dollar impact relative to the broader threat landscape.
The Drift attack, in particular, marked a tactical evolution. According to CoinDesk reporting, North Korean operatives attended conferences in person and built genuine relationships over months — a departure from remote phishing campaigns that characterized earlier DPRK operations. TRM Labs described the approach as North Korean hackers "moving faster."
Cross-chain bridges remain the single most exploited category of infrastructure in cryptocurrency. The historical record:
| Year | Major Bridge Exploit | Loss | |------|---------------------|------| | 2022 | Ronin Bridge | $624M | | 2022 | Wormhole Bridge | $326M | | 2022 | Nomad Bridge | $190M | | 2023 | Multichain | $126M | | 2026 | Kelp DAO / LayerZero | $292M | | 2026 | Drift Protocol | $285M |
The total exceeds $2.5 billion since 2021, according to aggregated data from DefiLlama and security firm reports.
The root cause varies by incident — validator key compromise (Ronin), smart contract bugs (Wormhole), trusted root exploits (Nomad), off-chain infrastructure manipulation (Kelp) — but the pattern is consistent: bridges aggregate large pools of wrapped assets that, if compromised, cascade across every chain where those assets circulate. The Kelp exploit demonstrated this when rsETH markets froze on more than 20 networks simultaneously.
The industry's response has followed a predictable pattern: post-exploit migration to a provider perceived as more secure, followed by architectural reforms by the exploited protocol. Whether this reactive cycle produces durable security improvements remains an open question.
The Kelp DAO and Drift Protocol exploits, occurring within 18 days of each other and both attributed to North Korean state actors, represent the most concentrated period of bridge-related losses since the Ronin hack of 2022. The immediate fallout — nearly $1 billion in asset migration, LayerZero's public reversal, and Chainlink's consolidation of cross-chain market share — will likely accelerate the industry's shift toward multi-verifier architectures and operator-mandated security minimums.
The deeper structural issue remains unresolved. Cross-chain bridges, by design, concentrate wrapped assets that circulate across dozens of networks. A single bridge failure can freeze markets across every chain where those assets are deployed. Until the industry develops verification frameworks that do not rely on trust assumptions about individual node operators — or until wrapped asset architectures can tolerate bridge failures without cascading solvency crises — bridges will remain the ecosystem's highest-value attack surface.
The data from TRM Labs on North Korea's growing share of crypto theft adds a geopolitical dimension: the most sophisticated attacks on DeFi infrastructure are now state-sponsored, well-funded, and operationally patient. The Drift hack's six-month, in-person social engineering campaign suggests that code audits alone are insufficient. The attack surface now includes the humans who operate the systems.