Kelp DAO is migrating its restaking token rsETH from LayerZero’s cross-chain framework to Chainlink’s Cross-Chain Interoperability Protocol (CCIP) after an April 18 exploit drained roughly 116,500 rsETH (about $292–300 million) from a LayerZero-powered bridge and sent shockwaves through DeFi lending markets. Attackers used the stolen rsETH as collateral on Aave v3 to borrow wrapped Ether, leading to asset freezes on Arbitrum and subsequent legal wrangling over control of tens of millions of dollars in ETH linked to the incident. Kelp describes the move to Chainlink’s CCIP and Cross-Chain Token Standard as a security-focused migration intended to harden rsETH’s cross-chain messaging and restore trust among holders. The incident has escalated into a public dispute over cross-chain security responsibility between Kelp DAO and LayerZero. LayerZero’s preliminary postmortem attributed the exploit to Kelp’s use of a single-DVN (decentralized verifier network) 1-of-1 configuration, which it says is unsafe for production and deviated from the default multi-DVN setup. Kelp disputes this framing, arguing that the single-verifier arrangement was approved during integration, widely used by other LayerZero applications, and presented as secure at the time. LayerZero co-founder Bryan Pellegrino has rejected Kelp’s version of events and said an external security postmortem is forthcoming, while LayerZero has pledged to stop approving cross-chain messages for apps using a single verifier and to push protocols toward multi-DVN configurations. Beyond the protocol-level blame, the exploit has become a test case for DeFi’s cross-chain risk, governance, and legal exposure. The hack is one of the largest DeFi security failures of the year and has prompted broader concerns about the fragility of cross-chain bridges and message verification setups. Aave and Arbitrum are embroiled in court over roughly $71 million in frozen ETH tied to the exploit, with Aave arguing the funds are needed to back rsETH and compensate affected users, while outside claimants seek to use the assets to satisfy unrelated judgments allegedly linked to North Korea–related crypto thefts. Kelp’s decision to abandon LayerZero in favor of Chainlink CCIP is being closely watched as other projects reassess their own cross-chain architectures, security assumptions, and reliance on third-party messaging layers. "entities":["Kelp DAO","rsETH","LayerZero","LayerZero Labs","Chainlink","Chainlink CCIP (Cross-Chain Interoperability Protocol)","Chainlink Cross-Chain Token Standard","Aave","Aave v3","Arbitrum","Arbitrum DAO","Arbitrum Security Council","Bryan Pellegrino","Drift (DEX)","North Korea-linked hacking groups"]}'}

AI-generated background, compiled from web sources — not editorial content.

More coverage

Explore the topic

More on LayerZero

Comments