Cross-chain bridge protocols lost $328.6 million across eight separate exploits in May 2026, according to PeckShield. The figure adds to what has become the worst year on record for bridge security, with cumulative 2026 losses exceeding $750 million through mid-May. North Korea's Lazarus Group ac...
"We made a mistake. The default 1-of-1 DVN configuration should never have shipped for high-value deployments." — Bryan Pellegrino, CEO, LayerZero Labs
Cross-chain bridge protocols lost $328.6 million across eight separate exploits in May 2026, according to PeckShield. The figure adds to what has become the worst year on record for bridge security, with cumulative 2026 losses exceeding $750 million through mid-May. North Korea's Lazarus Group accounts for an estimated 76% of all crypto hack losses this year.
The incidents span multiple architectures—guardian key compromise, off-chain backend manipulation, social engineering of infrastructure operators, and validation logic flaws. No single trust model has proven immune. Two new exploits on May 30 alone (Gravity Bridge, $5.4M; Alephium TokenBridge, $815K) demonstrate the attack cadence has not slowed despite months of industry alarm.
Bridge TVL stood at $21.94 billion as of March 2026, per DefiLlama. The ratio of funds stolen to funds secured—roughly 1.5% of TVL lost in a single month—raises fundamental questions about whether the cross-chain liquidity model can sustain institutional participation.
| Date | Protocol | Loss | Attack Vector | |------|----------|------|---------------| | Apr 18 | KelpDAO (LayerZero) | $292M | Social engineering + RPC node poisoning | | Apr 30 | Commons Bridge (Syndicate Labs) | ~$12M | Undisclosed | | May 18 | Verus-Ethereum Bridge | $11.6M | Missing source-amount validation | | May 30 | Gravity Bridge | $5.4M | Signing key compromise | | May 30 | Alephium TokenBridge | $815K | Off-chain backend vulnerability |
Note: PeckShield's $328.6M cumulative figure includes additional smaller incidents not individually detailed above.
The month averaged one bridge exploit every 3.8 days. April 2026 recorded 30 separate DeFi security incidents—nearly one per day—making it the most-hacked month in crypto history.
The $292 million KelpDAO exploit on April 18 remains the defining event of the current crisis. Chainalysis attributed the attack to North Korea's Lazarus Group, specifically its TraderTraitor subunit.
Attack mechanics: The breach did not exploit smart contract logic. An attacker socially engineered a LayerZero Labs developer beginning March 6, 2026, harvesting session keys to poison internal RPC nodes. The compromised nodes returned correct responses to LayerZero monitoring tools while feeding tampered data to the LayerZero Labs Decentralized Verifier Network (DVN). Since KelpDAO's rsETH route operated with a 1-of-1 DVN quorum—meaning a single poisoned node could authorize fraudulent cross-chain messages—the attacker extracted 116,500 rsETH across 20 chains.
Responsibility dispute: KelpDAO claims the 1-of-1 DVN was LayerZero's default configuration shipped for new deployments. LayerZero counters that Kelp originally deployed multi-DVN verification and manually downgraded to 1/1. On May 9, LayerZero CEO Bryan Pellegrino publicly stated: "We made a mistake." LayerZero published a formal incident report on May 18 acknowledging the default configuration was insufficient for high-value routes.
Partial recovery: KelpDAO paused contracts in time to block a second $95 million theft. The Arbitrum Security Council, coordinating with law enforcement, froze over 30,000 ETH of attacker funds downstream.
Aftermath: KelpDAO migrated to Chainlink's Cross-Chain Interoperability Protocol (CCIP), becoming one of the first major protocols to leave LayerZero post-exploit.
Two bridges fell on the same day—May 30—through entirely different attack vectors.
Gravity Bridge connects Ethereum to the Cosmos ecosystem via IBC. Attackers drained the Ethereum-side contract early on May 30. On-chain investigators, including PeckShield and The Block, point to a compromised signing key rather than a smart-contract flaw.
Stolen assets breakdown:
The attacker swapped most stablecoins into ETH, consolidating approximately 2,102 ETH ($4.23M), then routed portions through ChangeNow and Binance to obscure origins. Gravity Bridge halted operations following detection.
The exploit pattern—unauthorized withdrawals approved through compromised authorization—mirrors the Ronin Bridge attack of 2022 ($625M) and the Orbit Chain breach of January 2024 ($81.5M). Key custody remains the sector's single largest attack surface.
Blockchain security firm Blockaid detected the Alephium exploit at 14:22 UTC on May 30. The attacker completed the drain in seven minutes.
Initial reports vs. reality: Early analysis, including from Blockaid, indicated compromise of 3 of 4 guardian keys. Hours later, the Alephium team issued a correction: the root cause was an off-chain vulnerability in the bridge backend triggered in specific edge cases, not guardian key compromise.
Assets drained from Ethereum:
Additionally, 13.76 million unbacked ALPH tokens were minted on the Alephium chain, creating a secondary inflation event. The bridge was shut down and the team confirmed full neutralization of the exploit path. Alephium committed to user compensation.
The Verus-Ethereum bridge lost $11.58 million on May 18 at 23:55 UTC. The vulnerability was a missing source-amount validation in the bridge's Solidity logic, allowing the attacker to submit fake cross-chain transfer messages that tricked the bridge into releasing reserve funds.
The bounty deal: On May 22, the Verus community offered terms: return 4,052.4 ETH within 24 hours and retain 1,350 ETH (~$2.8M) as a bug bounty. In exchange, the community would halt investigations, refrain from pressing charges, and post public acknowledgement.
The attacker accepted. PeckShield confirmed the return of 4,052.4 ETH, approximately 75% of stolen funds.
This outcome reflects an emerging norm in DeFi security incidents: negotiated recovery over litigation. The calculus favors speed—recovered funds can be returned to users in days rather than years—but normalizes paying attackers millions for exploiting vulnerabilities they could have responsibly disclosed.
Analysis of 2026 bridge exploits reveals three dominant attack categories:
1. Key/Guardian Compromise (45% of losses) Includes KelpDAO (via social engineering), Gravity Bridge, and Orbit Chain (2024). The fundamental problem: bridges that concentrate signing authority in small key sets create single points of failure regardless of smart contract quality.
2. Off-Chain Infrastructure Manipulation (35% of losses) Includes KelpDAO's RPC poisoning and Alephium's backend vulnerability. On-chain verification is only as trustworthy as the data fed to it. Off-chain components—RPC nodes, relayer services, backend validation engines—are frequently less audited than smart contracts.
3. Validation Logic Flaws (20% of losses) Includes Verus (missing source-amount validation) and Wormhole 2022 (signature verification bypass). These are traditional software bugs in smart contracts that automated or manual code review should catch.
According to Sherlock's 2026 cross-chain security analysis, the real differentiator between exploited and resilient bridges is not the trust model itself but whether trust assumptions are "explicit, enforced, and monitored."
North Korea's Lazarus Group—umbrella designation for state-linked cyber actors tied to the Reconnaissance General Bureau—dominates 2026 crypto theft statistics.
2026 attribution:
Cumulative scale: Lazarus has stolen over $6 billion in cryptocurrency since 2017, according to Chainalysis and FBI attribution. The group's 2026 bridge focus represents an escalation in both sophistication and target selection.
Methodology evolution: TraderTraitor specializes in social engineering against technical staff, typically through fake recruiter pitches on LinkedIn. The KelpDAO exploit required weeks of preparation—compromising a developer on March 6 for an April 18 execution—demonstrating patience inconsistent with opportunistic criminal actors.
The KelpDAO disaster triggered measurable capital flight toward perceived safer infrastructure.
Chainlink CCIP adoption metrics:
Key migrations: Kraken replaced LayerZero with CCIP on May 14. KelpDAO itself migrated to CCIP. Coinbase, Lido, Maple Finance, and World Liberty Financial are current CCIP users.
CCIP security architecture differences:
The trade-off: CCIP's security premium comes with higher latency and fees. Protocols optimizing for speed over security—particularly those serving retail trading use cases—may resist migration.
Bridge exploits have produced more than $2.8 billion in cumulative losses since 2022, representing approximately 40% of all value hacked in Web3.
Year-by-year bridge losses:
| Year | Major Losses | Key Incidents | |------|-------------|---------------| | 2022 | ~$2.0B | Ronin ($625M), Wormhole ($320M), Nomad ($190M) | | 2023 | ~$300M | Multichain ($126M), others | | 2024 | ~$200M | Orbit Chain ($81.5M), others | | 2025 | ~$1.5B+ | Bybit ($1.4B), others | | 2026 (thru May) | $750M+ | KelpDAO ($292M), Drift ($286M), others |
2026 is on pace to exceed 2022's record. The re-acceleration after 2023–2024's relative calm correlates with: (a) rising bridge TVL providing larger targets, (b) Lazarus Group's increased operational tempo, and (c) proliferation of new bridges with immature security practices.
The cross-chain bridge sector faces a structural security deficit that incremental improvements have failed to resolve. May 2026's $328.6 million in losses occurred despite four years of post-Ronin industry awareness, multiple security framework proposals, and hundreds of millions spent on audits.
The core problem is architectural: bridges concentrate value in contracts whose security depends on the weakest link in their trust chain—whether that is a single DVN node, a compromised signing key, or an unaudited backend service. The economic incentive for attackers (state-sponsored and otherwise) scales with bridge TVL, which continues to grow as multichain activity expands.
Chainlink CCIP's rising adoption represents a market verdict: protocols are willing to pay higher costs for defense-in-depth architecture with higher minimum security thresholds. Whether this migration happens fast enough to prevent the next nine-figure exploit is an open question. Bridge TVL growth is outpacing security improvement, and Lazarus Group has demonstrated it can adapt to each new defensive measure.
The industry's current trajectory—$750M+ lost in five months—implies annualized bridge losses approaching $1.8 billion. That figure represents a direct tax on cross-chain economic activity that users, protocols, and institutions ultimately bear.