Cross-chain bridge protocols have hemorrhaged $340.7 million across 14 separate exploits in 2026 through June 1, according to aggregate data from PeckShield and CoinGabbar. The figure represents a concentrated failure mode: not smart contract bugs, but compromised off-chain infrastructure — signi...
"We made a mistake by allowing our DVN to act as a 1/1 DVN for high-value transactions. We didn't police what our DVN was securing, which created a risk we simply didn't see." — LayerZero Labs, Official Incident Statement (May 2026)
Cross-chain bridge protocols have hemorrhaged $340.7 million across 14 separate exploits in 2026 through June 1, according to aggregate data from PeckShield and CoinGabbar. The figure represents a concentrated failure mode: not smart contract bugs, but compromised off-chain infrastructure — signing keys, RPC nodes, and single-point-of-failure verification networks.
The single largest incident, a $292 million drain of KelpDAO's LayerZero-powered rsETH bridge on April 18, was attributed to North Korea's Lazarus Group (also tracked as TraderTraitor). The attack exploited a 1-of-1 Decentralized Verifier Network (DVN) configuration, allowing forged cross-chain messages to trigger real asset releases on Ethereum. PeckShield tracked eight major bridge incidents in May alone totaling $328.6 million, making it the worst month on record for bridge-specific losses.
The fallout has triggered a measurable migration away from vulnerable bridge architectures. Solv Protocol moved $700 million in tokenized Bitcoin infrastructure from LayerZero to Chainlink CCIP. LayerZero itself has ended support for 1-of-1 DVN configurations and is migrating all default pathways to 5-of-5 verification. The data points to a structural problem: bridges collectively hold over $21 billion in TVL as of March 2026, but the security models protecting those assets remain architecturally fragile.
Through June 1, 2026, cross-chain bridge protocols have lost $340.7 million across 14 confirmed exploits, according to tracking by CoinGabbar and PeckShield. Bridges now account for an estimated 40% of all value hacked in Web3 since 2022, with cumulative bridge losses exceeding $2.8 billion over that period.
The 2026 figures are on pace to eclipse prior annual records. For context, the full-year DeFi hack total across all protocol types exceeded $750 million by late May, per KuCoin Research. Bridge exploits represent approximately 45% of that aggregate — a disproportionate share given that bridges constitute a narrow infrastructure category.
The concentration of losses in two incidents — KelpDAO ($292 million) and Drift ($285 million) — accounts for the bulk of the total. Both exceeded any single DeFi exploit recorded in 2023 or 2024, according to data compiled by Phemex Research.
April 2026 was crypto's most-attacked month on record with 30 separate hack incidents, approximately one per day, according to DefiLlama data. The intensity has not abated: May added another $328.6 million in bridge-specific losses across eight tracked incidents.
On April 18, 2026, attackers drained 116,500 rsETH — approximately $292 million — from KelpDAO's cross-chain bridge powered by LayerZero's OFT (Omnichain Fungible Token) adapter on Ethereum. Chainalysis attributed the attack to North Korea's Lazarus Group.
The exploit contained no smart contract vulnerability. According to Chainalysis's post-mortem published under the title "Inside the KelpDAO Bridge Exploit," the attackers compromised KelpDAO's internal RPC nodes and simultaneously DDoS'd external nodes. This fed false data to the bridge's verification layer, which operated under a 1-of-1 DVN configuration — meaning a single compromised verifier was sufficient to authorize cross-chain messages.
The forged message instructed Ethereum's OFT adapter to release 116,500 rsETH against a token burn that never occurred on the source chain. The assets were stranded across 20 chains.
KelpDAO's incident response prevented a second $95 million theft by pausing contracts. The Arbitrum Security Council, coordinating with law enforcement, froze over 30,000 ETH of downstream attacker funds.
The blame dispute between KelpDAO and LayerZero was public and prolonged. KelpDAO stated on April 20 that LayerZero's default settings caused the vulnerability. LayerZero initially countered that KelpDAO had "manually migrated to a 1/1 config" away from the recommended multi-DVN default. On May 5, KelpDAO published evidence claiming LayerZero had approved the setup. By May 9, LayerZero acknowledged fault, stating in an official blog post: "We made a mistake."
OpenZeppelin, in a technical analysis titled "$292 Million Lost, Zero Bugs Found," noted that the exploit demonstrated a category of attack that code audits cannot catch — infrastructure-layer compromises targeting off-chain components that bridge protocols depend on.
PeckShield tracked eight major bridge exploits in May 2026 totaling $328.6 million. The individual incidents:
THORChain — $10.8 million (May 15): A vulnerability in the GG20 signature scheme, which governs how THORChain's nodes co-sign transactions, was exploited by what investigators believe was a malicious node operator. Assets were drained from liquidity pools across Bitcoin, Ethereum, BNB Chain, and Base — including 36.75 BTC. THORChain froze all trading and signing operations. Its native token RUNE dropped 14% on the news.
Verus-Ethereum Bridge — $11.58 million (May 18): An attacker submitted a forged transfer with zero real value on the Verus side. The bridge verified the proof and released real assets — 103.6 tBTC, 1,625 ETH, and 147,000 USDC — which were swapped into 5,402 ETH. Security researchers identified the flaw as a missing source-amount validation in the checkCCEValues function, a fix reportedly requiring approximately ten lines of Solidity code. The attacker later returned $8.5 million in ETH after the protocol offered a 1,350 ETH bug bounty.
Gravity Bridge — $5.4 million (May 30): The Cosmos-native cross-chain protocol was drained of $4.3 million in USDC, 274 ETH ($553,000), $434,000 in USDT, and PAYG tokens ($64,000). PeckShield flagged the incident. Blockchain investigator Specter identified the root cause as a signing key compromise at the validator authorization level. Portions of the stolen funds were routed through ChangeNow and Binance. The bridge remains halted.
Three bridge hacks in four days (THORChain, Verus, Echo Protocol) collectively drained over $32 million in mid-May, according to SpazioCrypto reporting.
The KelpDAO exploit triggered measurable capital reallocation in bridge infrastructure. Two migration events exceeded $700 million in combined value:
Solv Protocol: On May 7, 2026, Solv announced the migration of its entire tokenized Bitcoin portfolio — SolvBTC and xSolvBTC — from LayerZero to Chainlink CCIP. The move covered approximately $700 million in assets across deployments on Corn, Berachain, Rootstock, and TAC networks. According to CoinDesk reporting, Solv cited the KelpDAO incident and the single-verifier vulnerability as the primary motivation.
KelpDAO itself: Following the exploit, KelpDAO shifted its rsETH bridge infrastructure to Chainlink, moving away from the LayerZero setup that was compromised.
Chainlink CCIP operates on a different verification model. Each bridge lane relies on multiple independent Decentralized Oracle Networks, with 16 or more security-reviewed node operators handling validation — a structural contrast to the 1-of-1 configuration that failed at KelpDAO.
The migration volume — approaching $1 billion between Solv and KelpDAO alone — represents a material shift in market share among cross-chain messaging providers. It also signals that protocol teams are now evaluating bridge infrastructure providers on security architecture rather than transaction cost or deployment speed.
The 2026 exploit data reveals a pattern: the attack surface has shifted from smart contracts to off-chain infrastructure.
Signing key compromises accounted for the Gravity Bridge exploit. Investigators found no protocol-level coding flaw — the attacker gained access to validator-level authorization.
RPC node manipulation enabled the KelpDAO exploit. By controlling the data feed to the verification layer, attackers made the bridge's own security system authorize a fraudulent transaction.
Signature scheme vulnerabilities were exploited at THORChain, where the GG20 co-signing mechanism was compromised by a malicious node operator.
Missing input validation — a ten-line code fix — caused the $11.58 million Verus bridge loss.
The common thread: many cross-chain bridges operate using a small group of validators or a multisignature wallet. According to 1inch's analysis published in May 2026, this "simplifies development but creates a single point of failure if a majority of these validators are compromised through phishing, malware, social engineering, or insider collusion."
Bridges collectively held $21.94 billion in TVL as of March 2026, per DefiLlama. The security spend protecting those assets remains opaque, but the exploit frequency suggests a structural underinvestment relative to the value at risk.
LayerZero's response to the KelpDAO exploit included several structural changes announced in May 2026:
Beyond LayerZero's specific remediation, the broader industry is exploring architectural alternatives. ZK-proof-based bridges, which let one chain cryptographically verify the state of another without relying on trusted validators, represent the theoretical security frontier. Berkeley's zkBridge research demonstrates the feasibility of trustless cross-chain verification, though production deployment at scale remains limited.
Current best practices, according to a 2026 cross-chain security guide published by ChainsCoreLabs, recommend using light client proofs or ZK proofs wherever target ecosystems support them, with multisig bridges as a last resort.
The 2026 bridge exploit data presents a clear structural conclusion: the industry has solved for smart contract security faster than it has solved for infrastructure security. The most damaging attacks this year exploited signing keys, RPC nodes, and verification configurations — components that exist outside the scope of traditional code audits.
The $292 million KelpDAO incident and its aftermath — LayerZero's public admission of fault, the $1 billion migration to Chainlink CCIP, the end of single-verifier support — represent a forced reckoning with bridge architecture. Whether these measures prove sufficient depends on whether the industry treats bridge security as a one-time fix or an ongoing operational discipline.
Bridges collectively secure $21.94 billion in locked value. The 2026 exploit rate — 14 incidents in five months, averaging $24.3 million per exploit — implies that the current security equilibrium is unstable. ZK-proof-based verification offers a theoretical path to trustless bridging, but production deployment remains early-stage. Until that transition occurs, bridges remain the highest-value, lowest-security infrastructure in DeFi.