Major DeFi Projects Announce $14.5–$15B Migration to Chainlink After KelpDAO Hack

·

Announced migrations away from LayerZero-based cross-chain infrastructure have climbed to roughly $14.5 billion to $15 billion in value since the April hack of KelpDAO’s bridge, with BitGo, Mantle and Aave among the biggest names shifting to Chainlink’s Cross-Chain Interoperability Protocol, or CCIP.

That figure refers to announced commitments and planned migrations, not confirmed completed transfers. But the size of those commitments shows how a single exploit has reshaped infrastructure choices across decentralized finance, or DeFi, where applications depend on systems that move messages and assets between blockchains.

The catalyst was the April 18 exploit of KelpDAO’s LayerZero-based rsETH bridge. Chainalysis, the blockchain analytics firm, said: “On April 18, 2026, attackers linked to North Korea’s Lazarus Group stole ~$292 million (116,500 rsETH) from KelpDAO’s LayerZero bridge.” LayerZero and Chainalysis put the value at roughly $290 million to $293 million at the time and described the Lazarus attribution as preliminary.

The attack mattered well beyond KelpDAO because it highlighted risks in the off-chain systems that verify cross-chain activity, not just in smart contracts themselves. According to Chainalysis and LayerZero, internal RPC nodes feeding LayerZero’s verifier network were compromised while external RPCs were hit with distributed denial-of-service attacks, producing a false cross-chain attestation that let funds be released on Ethereum.

LayerZero said the issue was tied to how KelpDAO had configured the system, not to a flaw in the core protocol. In an April 19 incident statement, the company said, “We want to be unambiguous on this point: the LayerZero protocol itself functioned exactly as intended throughout this event.” LayerZero added that the incident was isolated to Kelp’s 1-of-1 decentralized verifier network, or DVN, setup, and said LayerZero Labs would no longer sign messages for applications using a 1/1 DVN. It also urged integrators to move to multi-verifier configurations.

KelpDAO responded by pausing affected rsETH contracts and blacklisting attacker addresses. Chainalysis said the Arbitrum Security Council, a governance body tied to the Arbitrum blockchain, coordinated a freeze on part of the downstream funds, with about 30,766 ETH frozen.

The infrastructure fallout became clearer over the following months.

On July 9, Mantle said it would migrate its Super Portal from LayerZero to Chainlink CCIP, covering about $2.5 billion in MNT token value.

Four days later, on July 13, Aave said it would make Chainlink CCIP the default cross-chain standard for the Aave app, its Stable Vaults and GHO cross-chain flows. Aave did not frame the move around a single dollar amount in the same way BitGo and Mantle did, but it marked one of DeFi’s largest lending protocols choosing a new default set of cross-chain rails after the Kelp incident.

Then on Aug. 4, BitGo said it would make Chainlink CCIP the exclusive cross-chain infrastructure for wrapped bitcoin, or WBTC, and future BitGo-issued assets. Press reports pegged WBTC exposure at roughly $7.3 billion to $7.7 billion. In its announcement, as quoted by press reports, BitGo said: “Security comes first. Always has. BitGo is migrating away from our legacy solution and selecting @chainlink CCIP as our exclusive cross-chain infrastructure provider…”

After BitGo’s decision, CoinDesk and other outlets put the total value of announced migrations from LayerZero-based setups to Chainlink CCIP at roughly $14.5 billion to $15 billion.

The broader damage from the KelpDAO exploit helps explain why those infrastructure decisions now carry more weight. CoinDesk reported that Aave’s total value locked fell by about $6.6 billion after the exploit, and that the protocol was left with roughly $196 million in Aave-specific bad debt after the attacker used stolen rsETH as collateral.

Taken together, the incident and its aftermath underscored a shift in how major crypto projects are evaluating cross-chain systems. The KelpDAO hack was not just a nearly $300 million theft. It became a stress test for the trust model behind cross-chain infrastructure, triggering policy changes at LayerZero, a partial freeze of stolen funds and a wave of public commitments by major issuers and protocols to move to competing rails.

Tags: #crypto, #defi, #chainlink, #layerzero