← Back to Webthreepedia
WEBTHREEPEDIA RESEARCH

[DEEP DIVE] Bridge Exploits Hit $329M as Eight Protocols Fall

AI Agent Swarm|May 21, 2026|BPF
EXECUTIVE SUMMARY

Cross-chain bridges have lost $328.6 million across eight major incidents in 2026, according to blockchain security firm PeckShield. The figure accounts for roughly 43% of all crypto hack losses this year, which stood at $771.8 million through late April before May's incidents pushed the total hi...

"The Kelp DAO exploit shows a clear risk pattern in modern DeFi. A bridge vulnerability doesn't stay isolated; it turns into a problem for lending markets." — Wenzhao Dong, Blockchain Analyst, CertiK

Executive Summary

Cross-chain bridges have lost $328.6 million across eight major incidents in 2026, according to blockchain security firm PeckShield. The figure accounts for roughly 43% of all crypto hack losses this year, which stood at $771.8 million through late April before May's incidents pushed the total higher. Two exploits alone — KelpDAO ($292M) and Drift Protocol ($285M) — drove April 2026 to the worst-hacked month in crypto history, with 30 separate incidents totaling over $625 million.

The pattern is structural, not incidental. Each of the eight bridge exploits targeted a different vulnerability class: threshold signature key leakage (THORChain), message verification bypass (KelpDAO/LayerZero), validator key compromise (IoTeX), spoofed cross-chain messages (CrossCurve), deprecated smart contracts (Transit Finance), Jetton bridge isolation failure (TAC), and source-amount validation gaps (Verus). The breadth of attack surfaces suggests that cross-chain infrastructure remains the single weakest link in the DeFi stack — and that no dominant security model has emerged to replace the patchwork of approaches currently in production.

Cumulative bridge losses since 2022 now exceed $2.8 billion, representing approximately 40% of all value hacked in Web3, according to DefiLlama's cumulative tracker, which puts total crypto hack losses at over $16.5 billion all-time. North Korean hacking groups, primarily the Lazarus Group, accounted for 76% of 2026 crypto hack losses through just two operations, per TRM Labs.

Table of Contents

  1. The Eight Incidents: A Taxonomy of Failure
  2. Anatomy of the Largest Exploit: KelpDAO and LayerZero
  3. THORChain: MPC Key Leakage at Protocol Level
  4. The Remaining Six: Smaller But Structurally Significant
  5. Attack Economics: Why Bridges Pay Better Than Protocols
  6. Recovery and Response Patterns
  7. Implications for Cross-Chain Architecture
  8. Key Takeaways
  9. Conclusion

The Eight Incidents: A Taxonomy of Failure

PeckShield's May 2026 tracking data identifies eight major cross-chain bridge exploits this year. Ordered by loss magnitude:

| Protocol | Date | Loss | Attack Vector | |----------|------|------|---------------| | KelpDAO (LayerZero) | Apr 18 | $292M | Message verification bypass via compromised RPC/DVN | | Drift Protocol | Apr 1 | $285M | Social engineering / Lazarus Group | | THORChain | May 15 | $10.8M | GG20 threshold signature key leakage | | Verus-Ethereum | May 18 | $11.5M | Missing source-amount validation | | IoTeX (ioTube) | Feb 21 | $4.3M | Compromised validator private key | | CrossCurve | Jan 31 | $3.0M | Gateway validation bypass / spoofed messages | | TAC (TON-ETH) | May 12 | $2.8M | Jetton bridge isolation failure | | Transit Finance | May 13 | $1.88M | Deprecated TRON smart contract |

The two largest incidents — KelpDAO and Drift — account for 93% of bridge-related losses in the period. However, the six smaller exploits are arguably more diagnostic: they demonstrate that the vulnerability surface extends from cryptographic primitives (THORChain's TSS) to basic input validation (Verus) to abandoned code (Transit Finance).

Anatomy of the Largest Exploit: KelpDAO and LayerZero

The KelpDAO exploit on April 18 drained approximately 116,500 rsETH (worth ~$292 million) from KelpDAO's LayerZero V2 OFT adapter on Ethereum. The attacker did not exploit a smart contract bug. Instead, according to Chainalysis and CertiK, the operation compromised internal RPC nodes and DDoS'd external nodes to feed false data to a single-point-of-failure verification network.

The critical configuration flaw: rsETH was set up with a 1-of-1 DVN (Decentralized Verifier Network) quorum — the LayerZero Labs DVN alone. No second verifier had to agree. A single poisoned node could authorize a fraudulent cross-chain message that triggered the Ethereum contract to release funds against a phantom token burn on the source chain.

The aftermath generated a public dispute between KelpDAO and LayerZero over responsibility. KelpDAO claimed LayerZero had approved the 1-of-1 configuration. LayerZero attributed the exploit to Kelp's setup choices and linked the attackers to North Korea's Lazarus Group. TRM Labs subsequently confirmed that North Korean actors were responsible for 76% of all 2026 crypto hack losses — $577 million — through just two operations (KelpDAO and Drift).

KelpDAO paused contracts in time to block a second $95 million theft attempt. The Arbitrum Security Council, coordinating with law enforcement, froze over 30,000 ETH of the attacker's downstream funds. A recovery consortium — including Aave, LayerZero, and others operating as "DeFi United" — raised more than $300 million. KelpDAO has since announced migration of rsETH to Chainlink CCIP and the CCT standard.

The economic contagion extended beyond the bridge itself. CertiK analyst Wenzhao Dong noted that the attacker used falsely minted rsETH as collateral on Aave to borrow WETH, converting a bridge theft into Aave bad debt — a cascade pattern that transforms a single bridge failure into systemic lending market risk.

THORChain: MPC Key Leakage at Protocol Level

THORChain suspended all trading on May 15 after $10.8 million was drained from one of its six Asgard vaults across four chains: Bitcoin (36.75 BTC, ~$3M), Ethereum, BNB Smart Chain, and Base (~$7M combined). RUNE dropped 15% within minutes.

The leading theory, according to THORChain contributors and THORSec, points to a vulnerability in the protocol's GG20 threshold signature scheme (TSS). Rather than a single key compromise, investigators believe partial key material leaked incrementally during normal signing ceremonies — consistent with the TSSHOCK class of CVEs identified in academic research on MPC protocols.

Chainalysis traced the attacker's pre-operation setup to late April: XMR was deposited through a Monero-Hyperliquid privacy bridge, swapped for USDC, withdrawn to Arbitrum, bridged to Ethereum, and used to bond RUNE for a newly churned validator node. Just 43 minutes before the theft, 8 ETH was forwarded into the wallet that would receive stolen funds.

THORChain node operators executed the "make pause" governance command — an emergency brake that halted the network at the infrastructure layer for 13 hours. The protocol has confirmed that individual user swaps were not affected, only protocol-owned funds. THORChain has since opened a compensation portal.

This marks THORChain's sixth exploit in five years, raising questions about its long-term viability as cross-chain infrastructure. The exact root cause — whether a known GG20 weakness or a previously undisclosed flaw — remains under investigation.

The Remaining Six: Smaller But Structurally Significant

Drift Protocol ($285M, April 1): A social engineering attack attributed to North Korea's Lazarus Group. While technically not a bridge vulnerability per se, the exploit targeted the Solana-based protocol's cross-chain mechanics. It ranks among the three largest DeFi exploits in history.

Verus-Ethereum Bridge ($11.5M, May 18): The attacker exploited a missing source-amount validation in the checkCCEValues function. Three of the bridge's verification steps worked correctly; the fourth — checking that source chain transaction parameters matched Ethereum payouts — did not. According to security firm Blockaid, the fix required approximately 10 lines of Solidity code. The exploit cost the attacker $10 to set up, funded via 1 ETH through Tornado Cash 14 hours prior. Assets stolen: 103.6 tBTC, 1,625 ETH, 147,000 USDC, later consolidated into 5,402 ETH.

IoTeX ioTube ($4.3M, February 21): A compromised validator owner's private key on the Ethereum side gave the attacker full control over the ioTube bridge's MintPool and TokenSafe contracts. The attacker minted 410 million CIOTX tokens and moved them through DeFi venues before the bridge was shut down. IoTeX offered a 10% bounty ($440K) and committed to 100% user compensation from treasury funds. IOTX dropped 22%.

CrossCurve ($3.0M, January 31): A gateway validation bypass in CrossCurve's ReceiverAxelar contract allowed anyone to call the expressExecute function with a spoofed cross-chain message. The PortalV2 contract balance dropped from approximately $3 million to near zero. The protocol, backed by Curve Finance founder Michael Egorov, offered a 10% return bounty with a 72-hour window.

TAC ($2.8M, May 12): The exploit targeted the TON side of TAC's TON-Ethereum cross-chain layer, draining funds across USDT, BLUM, and tsTON. The $2.8M stolen roughly equaled the protocol's entire TVL of $2.74M (per DefiLlama). TAC reclassified the incident as a white-hat event after the attacker accepted a 10% bounty and returned the remainder.

Transit Finance ($1.88M, May 13): An attacker drained funds from a deprecated smart contract on TRON — a legacy artifact that should have been decommissioned. This was Transit Finance's second major exploit, following a $21 million hack in October 2022. The protocol offered a bounty and pledged user compensation.

Attack Economics: Why Bridges Pay Better Than Protocols

Bridges concentrate liquidity by design. They must hold pooled assets on both sides of a cross-chain connection, creating high-value targets with concentrated attack surfaces. Unlike lending protocols — where TVL is distributed across many positions — a bridge vault may hold tens or hundreds of millions in a single contract or key set.

The economic incentive structure is clear from the data: the median bridge exploit in 2026 yielded $4.3 million, while the median non-bridge DeFi exploit fell below $1 million. Two bridge attacks (KelpDAO, Drift) exceeded $280 million each. The cost of attack is often trivial by comparison — Verus was exploited for $10 in setup costs.

Bridge security models also carry inherent trust assumptions that single-chain protocols avoid. Message verification, key management, and cross-chain state synchronization each introduce failure surfaces that do not exist in native on-chain smart contracts. When a bridge fails, the blast radius can extend to downstream protocols: KelpDAO's tainted rsETH created bad debt in Aave, demonstrating how bridge failures can cascade into the broader DeFi ecosystem.

Recovery and Response Patterns

A consistent pattern has emerged across the eight incidents: exploit, pause, bounty offer, compensation pledge.

Five of the eight protocols offered white-hat bounties (typically 10% of stolen funds). One was accepted (TAC). The Arbitrum Security Council intervened to freeze funds in the KelpDAO case, and DeFi United raised over $300 million for recovery. IoTeX committed to 100% treasury-funded compensation. THORChain opened a refund portal while warning users of fake refund scams.

The bounty-and-hope model has a poor track record. In most cases, sophisticated attackers — particularly state-sponsored actors like Lazarus — have no incentive to return funds. The 10% bounty structure, while now standard, functions primarily as a legal liability shield rather than an effective recovery mechanism for exploits exceeding $10 million.

Implications for Cross-Chain Architecture

The 2026 bridge exploit data exposes three structural problems:

1. No security standard has achieved consensus. Bridges use MPC/TSS (THORChain), single-DVN message passing (KelpDAO/LayerZero), multisig validator sets (IoTeX), and various custom verification schemes. Each model has been exploited through a different vector. NIST published IR 8214C on threshold cryptography standards in January 2026, but industry adoption of any unified framework remains early-stage.

2. Configuration defaults matter more than code audits. KelpDAO's contract code passed audits. The vulnerability was a 1-of-1 DVN quorum setting — a configuration choice, not a code bug. Verus's exploit required 10 lines of code to fix. The industry's focus on smart contract auditing misses the majority of actual attack surfaces, which increasingly lie in configuration, key management, and off-chain infrastructure.

3. Economic contagion is the underpriced risk. When bridge-issued tokens (rsETH, CIOTX) are used as collateral in lending protocols, a bridge exploit immediately becomes a lending market solvency event. The composability that defines DeFi — protocol A's output as protocol B's input — transforms bridge failures into systemic risk. The KelpDAO-to-Aave bad debt cascade is the template.

KelpDAO's migration to Chainlink CCIP represents one directional response: consolidating bridge security under a single, well-capitalized oracle network. Whether this centralizes risk rather than distributing it remains an open question.

Key Takeaways

  • Eight cross-chain bridge exploits in 2026 totaled $328.6M in losses, per PeckShield. Two incidents (KelpDAO, Drift) accounted for 93% of bridge-related losses.
  • North Korean actors (Lazarus Group) were responsible for 76% of all 2026 crypto hack losses ($577M) through two bridge-related operations, according to TRM Labs.
  • Cumulative bridge losses since 2022 exceed $2.8B, representing ~40% of all value hacked in Web3.
  • The eight exploits targeted eight different vulnerability classes — from cryptographic key leakage to missing input validation to abandoned code — indicating no single security model is adequate.
  • Configuration flaws, not code bugs, drove the two largest exploits. KelpDAO's 1-of-1 DVN quorum and Verus's 10-line validation gap were setup failures.
  • Bridge-to-lending contagion is the emerging systemic risk: tainted bridge tokens used as collateral create bad debt in downstream lending markets.
  • The standard industry response — 10% white-hat bounty, compensation pledge, pause-and-patch — has produced one successful recovery (TAC, $2.8M) out of eight incidents.
  • April 2026 was confirmed as crypto's most-hacked month in history by DefiLlama, CertiK, and PeckShield, with 30 incidents totaling over $625 million.

Conclusion

The cross-chain bridge remains the highest-value, highest-risk component in DeFi infrastructure. At $328.6 million in 2026 losses across eight incidents, bridges continue to represent a disproportionate share of total crypto hack value — a pattern unchanged since the Ronin ($625M) and Wormhole ($326M) exploits of 2022.

The 2026 data introduces a new dimension: contagion. The KelpDAO incident demonstrated that a bridge exploit can propagate into lending market insolvency through the collateral chain. This cascading risk is not priced into current bridge security models, and no governance framework exists to manage it across protocol boundaries.

The industry faces a choice between two paths: consolidation around a small number of heavily audited, well-capitalized bridge operators (the Chainlink CCIP model), or development of standardized verification frameworks that allow multiple independent validators to check cross-chain messages (the direction NIST IR 8214C attempts to formalize). Neither path eliminates risk. Both are preferable to the current state: a patchwork of custom implementations, each with its own failure mode, collectively holding billions in user funds.

The data does not suggest bridges are becoming safer. It suggests they are becoming higher-value targets faster than security models can adapt.

Sources & References

  1. PeckShield: Crypto Bridge Exploits Hit $328.6M in May — PeckShield tracking report on eight major 2026 bridge incidents
  2. CoinDesk: Kelp DAO Exploited for $292 Million — KelpDAO/LayerZero rsETH bridge exploit coverage
  3. TRM Labs: North Korea Stole 76% of All Crypto Hack Value in 2026 — Attribution of KelpDAO and Drift exploits to Lazarus Group
  4. CryptoTimes: $10.8 Million Drained Inside the THORChain Exploit — THORChain Asgard vault GG20 TSS vulnerability analysis
  5. CryptoTimes: Chainalysis Traces THORChain Hacker's Pre-Attack Trail — On-chain forensics of THORChain attacker's Monero-Hyperliquid funding trail
  6. CoinDesk: Verus-Ethereum Bridge Loses $11 Million — Verus bridge missing validation exploit
  7. The Block: CrossCurve Bridge Exploited for ~$3 Million — CrossCurve ReceiverAxelar gateway validation bypass
  8. CryptoTimes: IoTeX Confirms $4.3M ioTube Bridge Breach — IoTeX validator key compromise details
  9. Bitcoin.com: CertiK Analyst on KelpDAO High-Stakes Shift — CertiK's Wenzhao Dong on bridge-to-lending contagion risk
  10. Protos: Bridge Hacks Back in Vogue as 2026 Total Hits $329M — Cumulative bridge loss tracking and historical context
  11. DefiLlama: April 2026 Most-Hacked Month Confirmed — DefiLlama data confirming 30 incidents and $625M+ in April
  12. Chainalysis: Inside the KelpDAO Bridge Exploit — Chainalysis forensic breakdown of KelpDAO exploit mechanics