← Back to Webthreepedia
WEBTHREEPEDIA RESEARCH

[DEEP DIVE] Bridge Exploits Drain $329M in May, Systemic Fixes Elusive

Zephyra|May 31, 2026|BPF
EXECUTIVE SUMMARY

Cross-chain bridge protocols lost $328.6 million across eight separate exploits in May 2026, according to PeckShield. The figure adds to what has become the worst year on record for bridge security, with cumulative 2026 losses exceeding $750 million through mid-May. North Korea's Lazarus Group ac...

"We made a mistake. The default 1-of-1 DVN configuration should never have shipped for high-value deployments." — Bryan Pellegrino, CEO, LayerZero Labs

Executive Summary

Cross-chain bridge protocols lost $328.6 million across eight separate exploits in May 2026, according to PeckShield. The figure adds to what has become the worst year on record for bridge security, with cumulative 2026 losses exceeding $750 million through mid-May. North Korea's Lazarus Group accounts for an estimated 76% of all crypto hack losses this year.

The incidents span multiple architectures—guardian key compromise, off-chain backend manipulation, social engineering of infrastructure operators, and validation logic flaws. No single trust model has proven immune. Two new exploits on May 30 alone (Gravity Bridge, $5.4M; Alephium TokenBridge, $815K) demonstrate the attack cadence has not slowed despite months of industry alarm.

Bridge TVL stood at $21.94 billion as of March 2026, per DefiLlama. The ratio of funds stolen to funds secured—roughly 1.5% of TVL lost in a single month—raises fundamental questions about whether the cross-chain liquidity model can sustain institutional participation.

Table of Contents

  1. May 2026 Incident Timeline
  2. The KelpDAO-LayerZero Fallout
  3. May 30 Double Strike: Gravity Bridge and Alephium
  4. Verus Bridge: The Negotiated Recovery
  5. Attack Taxonomy and Root Causes
  6. Lazarus Group: State-Level Threat Actor
  7. Industry Response: The CCIP Migration
  8. Historical Context and Cumulative Losses
  9. Key Takeaways
  10. Conclusion

May 2026 Incident Timeline

| Date | Protocol | Loss | Attack Vector | |------|----------|------|---------------| | Apr 18 | KelpDAO (LayerZero) | $292M | Social engineering + RPC node poisoning | | Apr 30 | Commons Bridge (Syndicate Labs) | ~$12M | Undisclosed | | May 18 | Verus-Ethereum Bridge | $11.6M | Missing source-amount validation | | May 30 | Gravity Bridge | $5.4M | Signing key compromise | | May 30 | Alephium TokenBridge | $815K | Off-chain backend vulnerability |

Note: PeckShield's $328.6M cumulative figure includes additional smaller incidents not individually detailed above.

The month averaged one bridge exploit every 3.8 days. April 2026 recorded 30 separate DeFi security incidents—nearly one per day—making it the most-hacked month in crypto history.

The KelpDAO-LayerZero Fallout

The $292 million KelpDAO exploit on April 18 remains the defining event of the current crisis. Chainalysis attributed the attack to North Korea's Lazarus Group, specifically its TraderTraitor subunit.

Attack mechanics: The breach did not exploit smart contract logic. An attacker socially engineered a LayerZero Labs developer beginning March 6, 2026, harvesting session keys to poison internal RPC nodes. The compromised nodes returned correct responses to LayerZero monitoring tools while feeding tampered data to the LayerZero Labs Decentralized Verifier Network (DVN). Since KelpDAO's rsETH route operated with a 1-of-1 DVN quorum—meaning a single poisoned node could authorize fraudulent cross-chain messages—the attacker extracted 116,500 rsETH across 20 chains.

Responsibility dispute: KelpDAO claims the 1-of-1 DVN was LayerZero's default configuration shipped for new deployments. LayerZero counters that Kelp originally deployed multi-DVN verification and manually downgraded to 1/1. On May 9, LayerZero CEO Bryan Pellegrino publicly stated: "We made a mistake." LayerZero published a formal incident report on May 18 acknowledging the default configuration was insufficient for high-value routes.

Partial recovery: KelpDAO paused contracts in time to block a second $95 million theft. The Arbitrum Security Council, coordinating with law enforcement, froze over 30,000 ETH of attacker funds downstream.

Aftermath: KelpDAO migrated to Chainlink's Cross-Chain Interoperability Protocol (CCIP), becoming one of the first major protocols to leave LayerZero post-exploit.

May 30 Double Strike: Gravity Bridge and Alephium

Two bridges fell on the same day—May 30—through entirely different attack vectors.

Gravity Bridge ($5.4M)

Gravity Bridge connects Ethereum to the Cosmos ecosystem via IBC. Attackers drained the Ethereum-side contract early on May 30. On-chain investigators, including PeckShield and The Block, point to a compromised signing key rather than a smart-contract flaw.

Stolen assets breakdown:

  • $4.3 million USDC
  • 274 ETH ($553,000)
  • $434,000 USDT
  • 14,164 PAYG tokens ($64,000)

The attacker swapped most stablecoins into ETH, consolidating approximately 2,102 ETH ($4.23M), then routed portions through ChangeNow and Binance to obscure origins. Gravity Bridge halted operations following detection.

The exploit pattern—unauthorized withdrawals approved through compromised authorization—mirrors the Ronin Bridge attack of 2022 ($625M) and the Orbit Chain breach of January 2024 ($81.5M). Key custody remains the sector's single largest attack surface.

Alephium TokenBridge ($815K)

Blockchain security firm Blockaid detected the Alephium exploit at 14:22 UTC on May 30. The attacker completed the drain in seven minutes.

Initial reports vs. reality: Early analysis, including from Blockaid, indicated compromise of 3 of 4 guardian keys. Hours later, the Alephium team issued a correction: the root cause was an off-chain vulnerability in the bridge backend triggered in specific edge cases, not guardian key compromise.

Assets drained from Ethereum:

  • 200,967 USDT
  • 17,594 USDC
  • 5.18 WETH
  • 0.335 WBTC

Additionally, 13.76 million unbacked ALPH tokens were minted on the Alephium chain, creating a secondary inflation event. The bridge was shut down and the team confirmed full neutralization of the exploit path. Alephium committed to user compensation.

Verus Bridge: The Negotiated Recovery

The Verus-Ethereum bridge lost $11.58 million on May 18 at 23:55 UTC. The vulnerability was a missing source-amount validation in the bridge's Solidity logic, allowing the attacker to submit fake cross-chain transfer messages that tricked the bridge into releasing reserve funds.

The bounty deal: On May 22, the Verus community offered terms: return 4,052.4 ETH within 24 hours and retain 1,350 ETH (~$2.8M) as a bug bounty. In exchange, the community would halt investigations, refrain from pressing charges, and post public acknowledgement.

The attacker accepted. PeckShield confirmed the return of 4,052.4 ETH, approximately 75% of stolen funds.

This outcome reflects an emerging norm in DeFi security incidents: negotiated recovery over litigation. The calculus favors speed—recovered funds can be returned to users in days rather than years—but normalizes paying attackers millions for exploiting vulnerabilities they could have responsibly disclosed.

Attack Taxonomy and Root Causes

Analysis of 2026 bridge exploits reveals three dominant attack categories:

1. Key/Guardian Compromise (45% of losses) Includes KelpDAO (via social engineering), Gravity Bridge, and Orbit Chain (2024). The fundamental problem: bridges that concentrate signing authority in small key sets create single points of failure regardless of smart contract quality.

2. Off-Chain Infrastructure Manipulation (35% of losses) Includes KelpDAO's RPC poisoning and Alephium's backend vulnerability. On-chain verification is only as trustworthy as the data fed to it. Off-chain components—RPC nodes, relayer services, backend validation engines—are frequently less audited than smart contracts.

3. Validation Logic Flaws (20% of losses) Includes Verus (missing source-amount validation) and Wormhole 2022 (signature verification bypass). These are traditional software bugs in smart contracts that automated or manual code review should catch.

According to Sherlock's 2026 cross-chain security analysis, the real differentiator between exploited and resilient bridges is not the trust model itself but whether trust assumptions are "explicit, enforced, and monitored."

Lazarus Group: State-Level Threat Actor

North Korea's Lazarus Group—umbrella designation for state-linked cyber actors tied to the Reconnaissance General Bureau—dominates 2026 crypto theft statistics.

2026 attribution:

  • KelpDAO ($292M) — attributed to TraderTraitor subunit
  • Drift Protocol ($286M, April 1) — attributed to UNC4736 subcluster
  • Combined April take: $577M+ in 12 days

Cumulative scale: Lazarus has stolen over $6 billion in cryptocurrency since 2017, according to Chainalysis and FBI attribution. The group's 2026 bridge focus represents an escalation in both sophistication and target selection.

Methodology evolution: TraderTraitor specializes in social engineering against technical staff, typically through fake recruiter pitches on LinkedIn. The KelpDAO exploit required weeks of preparation—compromising a developer on March 6 for an April 18 execution—demonstrating patience inconsistent with opportunistic criminal actors.

Industry Response: The CCIP Migration

The KelpDAO disaster triggered measurable capital flight toward perceived safer infrastructure.

Chainlink CCIP adoption metrics:

  • $4 billion migrated to CCIP-connected infrastructure in weeks following the KelpDAO exploit, per a Chainlink executive
  • $60–70 billion in assets currently secured by CCIP cross-chain infrastructure
  • $18 billion processed in Q1 2026, up 62% quarter-over-quarter
  • 26 new enterprise integrations across 17 live blockchain networks in Q1

Key migrations: Kraken replaced LayerZero with CCIP on May 14. KelpDAO itself migrated to CCIP. Coinbase, Lido, Maple Finance, and World Liberty Financial are current CCIP users.

CCIP security architecture differences:

  • Minimum 16 node operators (vs. configurable 1-of-1 on LayerZero)
  • Multiple independent risk management networks
  • Built-in rate-limiting to prevent massive fund drains
  • Decentralized oracle network for verification

The trade-off: CCIP's security premium comes with higher latency and fees. Protocols optimizing for speed over security—particularly those serving retail trading use cases—may resist migration.

Historical Context and Cumulative Losses

Bridge exploits have produced more than $2.8 billion in cumulative losses since 2022, representing approximately 40% of all value hacked in Web3.

Year-by-year bridge losses:

| Year | Major Losses | Key Incidents | |------|-------------|---------------| | 2022 | ~$2.0B | Ronin ($625M), Wormhole ($320M), Nomad ($190M) | | 2023 | ~$300M | Multichain ($126M), others | | 2024 | ~$200M | Orbit Chain ($81.5M), others | | 2025 | ~$1.5B+ | Bybit ($1.4B), others | | 2026 (thru May) | $750M+ | KelpDAO ($292M), Drift ($286M), others |

2026 is on pace to exceed 2022's record. The re-acceleration after 2023–2024's relative calm correlates with: (a) rising bridge TVL providing larger targets, (b) Lazarus Group's increased operational tempo, and (c) proliferation of new bridges with immature security practices.

Key Takeaways

  • $328.6M lost across 8 bridge exploits in May 2026 alone. PeckShield data confirms the worst single-month loss figure in bridge history.
  • Key custody is the dominant attack surface. Three of the five largest 2026 exploits involved compromised signing authority, not smart contract bugs.
  • Off-chain infrastructure is under-audited. The KelpDAO and Alephium incidents both exploited components outside the smart contract layer—RPC nodes and backend services that receive less security scrutiny.
  • Lazarus Group dominates 2026 losses. State-sponsored actors account for 76% of all crypto theft this year, with bridge protocols as primary targets.
  • Capital is migrating to CCIP. $4B moved to Chainlink CCIP infrastructure post-KelpDAO, but adoption requires accepting higher costs and latency.
  • Negotiated recovery is becoming standard. The Verus deal—attacker keeps $2.8M, returns 75%—reflects the industry's pragmatic acceptance that legal recovery is too slow.
  • Bridge TVL of $21.94B creates persistent incentive. As long as bridges hold billions in concentrated liquidity, they remain the highest-ROI target for sophisticated threat actors.

Conclusion

The cross-chain bridge sector faces a structural security deficit that incremental improvements have failed to resolve. May 2026's $328.6 million in losses occurred despite four years of post-Ronin industry awareness, multiple security framework proposals, and hundreds of millions spent on audits.

The core problem is architectural: bridges concentrate value in contracts whose security depends on the weakest link in their trust chain—whether that is a single DVN node, a compromised signing key, or an unaudited backend service. The economic incentive for attackers (state-sponsored and otherwise) scales with bridge TVL, which continues to grow as multichain activity expands.

Chainlink CCIP's rising adoption represents a market verdict: protocols are willing to pay higher costs for defense-in-depth architecture with higher minimum security thresholds. Whether this migration happens fast enough to prevent the next nine-figure exploit is an open question. Bridge TVL growth is outpacing security improvement, and Lazarus Group has demonstrated it can adapt to each new defensive measure.

The industry's current trajectory—$750M+ lost in five months—implies annualized bridge losses approaching $1.8 billion. That figure represents a direct tax on cross-chain economic activity that users, protocols, and institutions ultimately bear.

Sources & References

  1. Crypto Bridge Exploits Hit $328.6M in May as PeckShield Tracks 8 Major Incidents — Bitcoin.com, May 2026
  2. Inside the KelpDAO Bridge Exploit — Chainalysis blog, April 2026
  3. LayerZero says it 'made a mistake' in $292 Million Kelp exploit — CoinDesk, May 9, 2026
  4. Gravity Bridge Hit in $5.4M Exploit Amid Suspected Key Compromise — CryptoTimes, May 30, 2026
  5. Cosmos-based Gravity Bridge drained of $5.4 million in suspected key compromise — The Block, May 30, 2026
  6. Alephium Bridge Exploited for $815K, 13.76M Unbacked ALPH Minted — CryptoTimes, May 30, 2026
  7. Alephium Reveals Cause of $815K Bridge Exploit, Promises Compensation — CryptoTimes, May 30, 2026
  8. Verus Bridge Exploiter Returns 4,052 ETH, Retains $2.8 Million Bounty — The Block, May 22, 2026
  9. Chainlink executive says $4B moved to CCIP after major crypto exploit — TheStreet, May 2026
  10. Kraken Adopts Chainlink CCIP as Cross-Chain Standard, Replacing LayerZero — CoinAlert News, May 14, 2026
  11. North Korea's $6 Billion Crypto Crime Spree: The Full Picture in 2026 — Crypto Impact Hub, 2026
  12. Top Crypto Hacks of 2026: Bridge Exploits and Sophisticated Operations Drive Over $750 Million in Losses — KuCoin Blog, 2026
  13. Cross-Chain Security in 2026: Threat Models, Trust Assumptions, and Failure Modes — Sherlock, 2026
  14. LayerZero, Lazarus and KelpDAO: The Full Story Behind the $292M Bridge Exploit — CoinPaper, 2026