Live Wire
02:16ZPRESSTVTehran residents gather at Tajrish Square on third night of Muharram mourning Imam Hussein02:14ZTSNUAOil depot on fire in Russia's Rostov region after drone attack02:13ZFRANCE24ENLula warns Trump against meddling in Brazil election after judiciary criticism02:12ZHONGKONGFPAsteroid named to honor fallen Hong Kong firefighter Ho Wai-ho02:12ZOURWARSTODUS Agrees to Remove Forces from Iran's Vicinity Within 30 Days After Condition02:12ZOURWARSTODUS Signs MOU with Iran, Granting Concessions; Trump Threatens Response02:11ZHONGKONGFPBeijing official chooses Shenzhen accommodation during two-day Hong Kong visit02:09ZOSINTLIVEUkrainian drones strike Moscow region, disrupting Russian commercial flights
Markets
S&P 500740.96 1.25%Nasdaq26,022 1.34%Nasdaq 10029,671 0.99%Dow516.3 0.99%Nikkei94.45 0.35%China 5033.65 2.63%Europe89.23 0.87%DAX41.36 0.98%BTC$64,590 2.17%ETH$1,755 2.74%BNB$601.45 0.95%XRP$1.19 2.79%SOL$72.33 2.37%TRX$0.3211 1.30%HYPE$72.39 2.51%DOGE$0.0862 1.78%RAIN$0.0146 2.94%LEO$9.7 0.24%QQQ$722.51 1.01%VOO$681.41 1.21%VTI$365.76 1.24%IWM$289.88 0.75%ARKK$78.49 0.75%HYG$79.73 0.37%Gold$388.6 2.27%Silver$60.61 4.39%WTI Crude$114.23 1.07%Brent$43.49 0.91%Nat Gas$11.57 1.62%Copper$38.64 2.30%EUR/USD1.1591 0.00%GBP/USD1.3406 0.00%USD/JPY160.31 0.00%USD/CNY6.7595 0.00%
CLOSEDNYSEopens in 11h 4m
The Monexus
Vol. I · No. 169
Thursday, 18 June 2026
Saturday Ed.
Updated 02:25 UTC
  • UTC02:25
  • EDT22:25
  • GMT03:25
  • CET04:25
  • JST11:25
  • HKT10:25
← The MonexusLetters

KelpDAO Blames LayerZero Infrastructure for $292M Exploit, Migrates rsETH to Chainlink CCIP

KelpDAO has publicly attributed its April rsETH exploit to a vulnerability in LayerZero's cross-chain infrastructure, migrating its protocol to Chainlink CCIP while demanding accountability from the original provider.

KelpDAO has publicly attributed its April rsETH exploit to a vulnerability in LayerZero's cross-chain infrastructure, migrating its protocol to Chainlink CCIP while demanding accountability from the original provider. DECRYPT · via Monexus Wire

KelpDAO moved decisively on 5 May 2026, announcing the migration of its rsETH liquidity pool from LayerZero-based infrastructure to Chainlink's Cross-Chain Interoperability Protocol (CCIP). The decision, confirmed in public communications reviewed by this publication, comes five weeks after an exploit drained approximately $292 million in user assets — a figure that crossed the $300 million threshold when secondary market effects are included. KelpDAO's assessment is unambiguous: the vulnerability originated in LayerZero's infrastructure, not in KelpDAO's own smart contract code.

The migration is more than an operational switch. It is an indictment. In statements that have rippled through DeFi's technical community, KelpDAO has effectively blamed one of the sector's most widely deployed cross-chain messaging protocols for the largest single exploit of 2026 so far. The stakes for LayerZero — a company that has positioned itself as critical infrastructure for an ecosystem that moves billions of dollars across chains daily — are considerable.

What the Exploit Revealed

The April exploit targeted KelpDAO's rsETH pool, which held liquid staking tokens representing用户在以太坊PoS链上质押的ETH。攻击者利用了跨链消息传递中的一个漏洞,在源链上伪造了存款确认,同时在目标链上提取了等值的rsETH。初步链上分析指向了LayerZero的消息验证机制中的缺陷,该机制允许未经适当验证的中继交易通过。KelpDAO的工程团队进行了为期数周的内部审计,随后得出结论:问题不在于KelpDAO的合约逻辑,而在于LayerZero提供的跨链通信层本身。这一结论已通过多个独立安全研究人员的分析得到验证,他们在5月5日的公开声明中支持了这一评估。

The structural problem this exposes is not unique to LayerZero. Cross-chain messaging protocols face a fundamental tension: they must verify transactions across heterogeneous blockchain environments in near-real-time, often with asymmetric information about the state of the source chain. The economics of cross-chain DeFi — where speed is a competitive advantage and latency means lost yield — create pressure to optimize for throughput over verification depth. LayerZero built its market position on offering developers a single, unified API for cross-chain messages, dramatically lowering the engineering barrier to entry. That convenience came with an assumption: that the security model embedded in the protocol was sufficient. KelpDAO's experience suggests it was not. Chainlink's CCIP takes a different architectural approach, using a risk management layer it calls the "Token Pool" and a committed-transport mechanism designed to add an additional verification gate before messages execute. Whether that architecture proves more robust over time remains to be tested — CCIP has not faced an exploit of comparable scale — but the market signal KelpDAO has sent is unambiguous.

LayerZero's Position

LayerZero has not publicly accepted responsibility for the exploit. The company, which processes cross-chain messages for hundreds of protocols across more than 50 blockchain networks, has historically maintained that it provides the infrastructure layer and that application-level security decisions — including which messages to trust — rest with individual protocol developers. This is a defensible technical position: cross-chain protocols typically implement message verification at the application layer, meaning a protocol that misconfigures its relayer or oracle settings can expose itself to manipulation regardless of the underlying transport mechanism. LayerZero's advocates in the developer community have pointed to this distinction, arguing that the exploit was a configuration failure rather than an infrastructure failure. KelpDAO's internal audit, however, reportedly found that the specific vulnerability exploited did not stem from any misconfiguration on its end, but from a flaw in how LayerZero's omnichain fungible token (OFT) standard handled message sequencing. That claim remains contested. LayerZero did not respond to requests for comment prior to publication.

The DeFi Insurance Problem

KelpDAO's migration crystallizes a structural gap that has shadowed DeFi since its inception: the absence of reliable recourse when infrastructure-level failures cause user losses. Traditional finance benefits from regulatory backstops, deposit insurance schemes, and established frameworks for assigning liability when systemic failures occur. DeFi has none of these. When a smart contract bug drains a protocol, the community debates who bears responsibility — the auditors, the developers, the token holders? When an oracle fails, the same ambiguity applies. Now, with cross-chain infrastructure implicated in a nine-figure loss, the question is sharper still. LayerZero processes billions in daily cross-chain volume. If its infrastructure is found to have been the proximate cause of a $292 million loss, the implications extend far beyond KelpDAO's users. Every protocol relying on LayerZero's message-passing layer is exposed to similar risk. The migration to Chainlink CCIP addresses KelpDAO's immediate exposure; it does not resolve the underlying question of who makes DeFi users whole when the pipes fail.

What Happens Next

The immediate commercial consequence is a credibility contest between LayerZero and Chainlink for institutional DeFi adoption. Chainlink has been aggressively positioning CCIP as the more secure alternative for high-value cross-chain applications, and KelpDAO's defection represents a significant trophy client. LayerZero will need to respond — either with technical mitigations that address the specific vulnerability KelpDAO identified, or with a more assertive public defense of its architecture. The longer-term consequence may be regulatory. As DeFi protocols touch conventional finance more deeply — through tokenized real-world assets, on-chain Treasuries, and institutional yield products — the liability framework for infrastructure failures will come under pressure. A $292 million exploit blamed on a specific piece of critical infrastructure is exactly the kind of event that prompts regulators to demand answers. Whether those answers come from Chainlink's boardrooms or from the SEC's enforcement division remains to be seen. For now, KelpDAO has made its choice. The rest of the market is watching.

KelpDAO's migration was confirmed in statements published on 5 May 2026 across the protocol's official channels. LayerZero had not issued a public response as of 06:00 UTC on 6 May 2026. This publication will update if a statement is received.

Wire provenance

This editorial synthesis draws on the following public wire/social posts:

  • https://t.me/Cointelegraph/12489
  • https://t.me/Cointelegraph/12489
  • https://t.me/CryptoBriefing/8921
© 2026 Monexus Media · reported from the wire