started · updated
KelpDAO exploit triggers $15B DeFi migration and Aave asset decline
The April 18 KelpDAO bridge exploit, attributed to North Korea’s Lazarus Group, has triggered a massive shift in decentralized finance (DeFi) infrastructure. The attack involved forging a cross-chain message to drain 116,500 rsETH, valued at approximately $292 million. The stolen assets were subsequently used as collateral on Aave to borrow real ETH, creating significant bad debt across lending protocols.
In the aftermath, Aave has seen its total value locked (TVL) drop by 43% since the incident, falling to $14.9 billion. While industry allies helped restore collateral and stabilize markets by late May, depositor confidence has not fully recovered.
The exploit has also catalyzed a large-scale migration of assets away from LayerZero toward Chainlink CCIP. Approximately $15 billion in total value has migrated, including $7.4 billion in WBTC from BitGo and $2.5 billion from Mantle. This shift is driven by concerns over LayerZero’s verifier model compared to Chainlink’s multi-node requirement. Notably, Wyoming’s Stable Token Commission has also selected Chainlink CCIP as its exclusive infrastructure provider.
Entities
Aave · Chainlink · KelpDAO · LayerZero · Lazarus Group