Cryip
  • Home
  • Crypto News Today
  • Research & Analysis
  • Reviews & Comparisons
  • Learn Crypto
  • Features
No Result
View All Result
Cryip
  • Home
  • Crypto News Today
  • Research & Analysis
  • Reviews & Comparisons
  • Learn Crypto
  • Features
No Result
View All Result
Cryip
No Result
View All Result
Home Crypto News Today Security & Hacks

Kelp DAO Migrates rsETH from LayerZero to Chainlink CCIP After $292M Exploit

Kelp DAO shifts rsETH from LayerZero to Chainlink CCIP after a $292M exploit, highlighting the growing priority of security over speed in cross-chain DeFi infrastructure.

Saravana Kumar Mahendran by Saravana Kumar Mahendran
May 6, 2026
in Security & Hacks
0 0
Kelp DAO Migrates rsETH from LayerZero to Chainlink CCIP

Created by Cryip

Share on FacebookShare on Twitter
MakeCryipCryippreferred onGoogle

In a decisive move that underscores the high stakes of cross-chain infrastructure in DeFi, Kelp DAO has announced the migration of its liquid restaking token, rsETH, from LayerZero’s Omnichain Fungible Token (OFT) standard to Chainlink’s Cross-Chain Interoperability Protocol (CCIP). The decision, detailed in a May 5, 2026 X post, comes just weeks after a massive April 18 exploit drained approximately 116,500 rsETH, valued at around $292 million, marking one of the largest DeFi hacks of the year.

Kelp DAO framed the migration explicitly as a security upgrade: “After the recent LayerZero exploit, we are taking steps to ensure rsETH is fully secure, which is why we are migrating to chainlink CCIP.” The team emphasized that independent security reports point to vulnerabilities in LayerZero’s infrastructure as the root cause. This move signals a broader industry reckoning with the trade-offs between speed, flexibility, and resilience in bridging solutions.

After the recent LayerZero exploit, we are taking steps to ensure rsETH is fully secure, which is why we are migrating to @chainlink CCIP.

From the April 18 incident, it is clear that LayerZero’s own infrastructure was exploited, resulting in $300M in losses across DeFi.… https://t.co/beIrfZZLlh

— Kelp (@KelpDAO) May 5, 2026

The Exploit: What Happened and Why It Matters

On April 18, 2026, hackers exploited Kelp DAO’s rsETH bridge powered by LayerZero by forging a cross-chain message. This triggered the unauthorized release of a massive volume of rsETH from Ethereum mainnet escrow without any corresponding token burn on the source chain.

The stolen rsETH was quickly used as collateral on Aave v3 to borrow large amounts of wrapped ETH. The exploit caused immediate liquidity shocks, frozen assets across connected protocols, and significant market disruptions. Security analyses linked the attack to North Korea’s Lazarus Group and highlighted a critical 1-of-1 verifier configuration as the main vulnerability.

A public blame game quickly erupted. LayerZero argued that Kelp had chosen a risky single-verifier setup despite warnings, while Kelp and several independent reports pointed to fundamental weaknesses in LayerZero’s infrastructure and approval process. This incident was more than just a costly hack. It exposed the real-world dangers of over-reliance on flexible but potentially fragile cross-chain systems and severely damaged trust in rsETH and the broader liquid restaking sector.

LayerZero OFT vs Chainlink CCIP: Detailed Comparison

To understand why Kelp DAO made this strategic shift, here is a clear side-by-side comparison of the two protocols:

Aspect LayerZero Chainlink CCIP
Security Model Flexible, application-owned security via multiple DVNs Defense-in-depth with Commit DON, Execute DON and dedicated Risk Management Network
Verifier / Validation Can be configured as 1-of-1 (single point of failure) Multiple independent networks + RMN for anomaly detection
Speed Faster (often 30 seconds – 2 minutes) Slower (typically 10–20+ minutes)
Chain Support Very broad (70+ chains) More selective but high-quality (15+ and expanding)
Customization Very High Standardized and secure-by-default
Risk Management Project-dependent Dedicated dynamic RMN
Track Record Multiple exploits linked to weak configs No major value loss on core protocol
Cost Generally lower Slightly higher due to added security layers

Why Chainlink CCIP? Security Architecture in Focus

Chainlink CCIP stands out for its separation of concerns across independent networks and its dedicated Risk Management Network that can dynamically respond to threats. Sergey Nazarov and the Chainlink team have long emphasized this modular, defense-in-depth design.

Kelp’s migration to CCIP along with Chainlink’s Cross-Chain Token (CCT) standard aims to provide users with far more reliable bridging. The transition is already visible in Kelp’s GitHub repositories, with new CCIP contracts listed alongside legacy LayerZero ones. This is a calculated strategic pivot toward infrastructure that puts verifiable security first.

Kelp’s decision is smart and responsible. After suffering a nearly $300 million exploit, choosing the more conservative and battle-tested security model makes complete sense. While users may face some short-term friction during migration, the long-term gain in credibility and reduced attack surface is significant.

Broader Industry Implications and Competitor Landscape

The Kelp-LayerZero incident has intensified scrutiny on cross-chain solutions. Other bridges like Axelar, Wormhole, and multi-bridge aggregators will likely face increased demands for proof of multi-verifier resilience. Chainlink strengthens its leadership in both oracles and interoperability as DeFi continues to scale.

For rsETH holders and the wider community, this reinforces the importance of DYOR on underlying bridge infrastructure. Liquid restaking tokens offer attractive yields but come with bridge and smart contract risks.

Opportunities and Cautions

Aave is currently fighting in a U.S. federal court to unfreeze approximately $71 million worth of ETH on Arbitrum that was frozen following the Kelp DAO exploit. The protocol has warned that prolonged freezing of these assets could cause irreparable harm to users and the wider DeFi ecosystem.

Kelp DAO, backed by strong investors including Laser Digital and SCB, is positioning itself for recovery through enhanced security and upcoming real-world utility features like KUSD. The migration could attract more security-conscious capital into the restaking sector.

Challenges remain, including smooth technical execution, liquidity management during transition, and ongoing recovery efforts. However, DeFi has repeatedly shown its ability to adapt quickly.

In the maturing 2026 crypto market, security is no longer optional. It is table stakes. Kelp’s willingness to migrate to a stronger infrastructure rather than defend the old setup demonstrates real accountability. This move sets a positive precedent and will likely encourage other protocols to prioritize robust solutions like Chainlink CCIP. While LayerZero remains powerful for certain use cases, high-value tokens like rsETH belong on more secure foundations.

This event is not the end of cross-chain innovation but a necessary stress test that pushes the entire ecosystem toward greater maturity. Users and projects that prioritize verifiable security will be best positioned for long-term success.

AI Disclosure: Cryip uses AI-assisted tools to help refine language — correcting spelling and grammar and simplifying complex terms for readability.

We do this to make crypto topics easier to understand for readers at all experience levels. AI does not draft facts, sources, or conclusions. Every article is reviewed and approved by a human editor before publication. Read our full AI Use & Content Policy.

Disclaimer: Cryip’s content is strictly for informational purposes and does not constitute financial, legal, or investment advice. Asset references are not endorsements, and readers assume full responsibility for any financial decisions.
Tags: crypto security
Saravana Kumar Mahendran

Saravana Kumar Mahendran

Saravana Kumar Mahendran is a crypto security analyst and blockchain researcher at Cryip, focusing on DeFi protocol exploits, Web3 security systems, and on-chain investigation. His research applies OSINT and fact-checking methodology to security incidents, drawing on certifications in cybersecurity and data analytics (LinkedIn Learning), and DeFi deep-dive training (Binance Academy). His work has been cited by Sherlock, Rekt.news, and Halborn Security.

Related Posts

Bitcoin Security Consortium Launches With $15M to Strengthen BTC Security
Market Updates

Saylor’s Strategy Joins $15M Bitcoin Security Consortium to Strengthen BTC Security

by Sathish Kumar Kaliraj
July 23, 2026

Major financial institutions and Bitcoin-focused companies have formed the Bitcoin Security Consortium (BSC) to help strengthen the network's long-term security...

Read moreDetails
Ledger Researchers Disclose Tangem Card Flaw

Ledger Researchers Reveal Laser Flaw in Tangem Cards as Firm Downplays User Risk

July 10, 2026 - Updated on July 16, 2026
Hackers Target Injective Wallet Keys Through Compromised npm Package

Malicious Injective SDK Package Targets Private Keys and Seed Phrases

July 10, 2026
Secret Network Proposes SCRT Move to Arbitrum as AI Exploit Risks Reshape Security Priorities

Secret Network Proposes SCRT Move to Arbitrum as AI Exploit Risks Reshape Security Priorities

July 8, 2026
TRON Introduces Quantum-Safe Signatures

TRON Introduces Quantum-Safe Signatures Across Nile Testnet

July 3, 2026
Taiko Bridge Reopens After $1.7 Million Hack, Restores Cross-Chain Operation

Taiko Bridge Reopens After $1.7 Million Hack, Restores Cross-Chain Operations

July 2, 2026
Microsoft Uncovers Crypto Malware That Spreads Like a Worm and Hides Behind Tor

Microsoft Warns of CryptoBandits Malware Using USB Worm Tactics and Tor Network

June 19, 2026
Next Post
Strategy Reports $12.54B Q1 Net Loss, Signals Potential Bitcoin Sale to Fund Dividend Obligations

Strategy Reports $12.54B Q1 Net Loss, Signals Potential Bitcoin Sale to Fund Dividend Obligations

Solana and Google Cloud Launch Pay.sh for Stablecoin Payments to AI Agents

Solana and Google Cloud Launch Pay.sh for Stablecoin Payments to AI Agents

Recommended

  • All
  • Crypto News Today
Putin Signs Russia’s First Comprehensive Crypto Law, Effective September 1

Putin Signs Russia’s First Comprehensive Crypto Law, Effective September 1

August 6, 2026
Coinbase Revises Advanced Trade Markets With Six Pair Suspensions

Coinbase to End Trading for Six Non-USD Pairs on Advanced Trade

August 6, 2026
Mysten Labs' Sam Blackshear Leaves to Join Anthropic for AI Security Research

Mysten Labs’ Sam Blackshear Leaves to Join Anthropic for AI Security Research

August 6, 2026
Circle Q2 2026 Revenue Hits $701M as USDC Volume Reaches $14.8

Circle Q2 2026 Revenue Hits $701M as USDC Volume Reaches $14.8

August 5, 2026
Binance Files $472 Million Lawsuit Against RedotPay

Binance Files $472 Million Lawsuit Against RedotPay

August 5, 2026 - Updated on August 6, 2026
South Korea Confirms No Delay to Crypto Tax, But Repeal Bill Sits in Limbo

South Korea Confirms No Delay to Crypto Tax, But Repeal Bill Sits in Limbo

August 5, 2026
MARA Transfers 7,500 BTC to Two Prime, a Firm It Partly Owns

MARA Transfers 7,500 BTC to Two Prime, a Firm It Partly Owns

August 5, 2026
Cloudflare’s AI Agent Wallet Comes With Money, But Identity Is Optional

Cloudflare’s AI Agent Wallet Comes With Money, But Identity Is Optional

August 5, 2026

Cryip focuses on crypto research and on-chain analysis, supported by coverage of markets, regulation, security events, and blockchain ecosystems.

Recent Posts

  • EU Warns Crypto Scammers Exploit MiCA Transition as Users Move Funds
  • Putin Signs Russia’s First Comprehensive Crypto Law, Effective September 1
  • Coinbase to End Trading for Six Non-USD Pairs on Advanced Trade

Categories

  • AI × Crypto
  • Data & Dashboards
  • DeFi Basics
  • Investing Basics
  • Market & Price
  • Market Updates
  • On-Chain Analysis
  • OpSec
  • Policy & Regulation
  • Post Mortems
  • Press Release
  • Reports
  • Scams & Fraud
  • Security & Hacks
  • Stablecoins
  • Tokenomics
  • VC & Funding
  • Wallets & Custody

Company

  • About Us
  • Contact Us
  • Editorial Standards & Integrity
  • Our Team
  • Privacy Policy
  • Review Methodology
  • Terms and Conditions
  • Trust, Disclosures & Independence

© 2026 Cryip - Research-Driven Crypto Analysis & News by Hashlays.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

No Result
View All Result
  • Home
  • Crypto News Today
  • Research & Analysis
  • Reviews & Comparisons
  • Learn Crypto
  • Features

© 2026 Cryip - Research-Driven Crypto Analysis & News by Hashlays.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.