Monitor this situation.
Unsubscribe anytime.
[SITUATION] · [QUIET] · [TECHNOLOGY]
2 clusters · 2 sources · 14 days · First seen · Last updated
DeFi security risks and infrastructure shifts
Overview
The KelpDAO bridge exploit, attributed to North Korea’s Lazarus Group, involved the theft of 116,500 rsETH valued at approximately $292 million. The attackers used the stolen assets as collateral on Aave to borrow real ETH, resulting in significant bad debt and a 43% drop in Aave’s total value locked.
This incident catalyzed a massive migration of approximately $15 billion in assets from LayerZero to Chainlink CCIP, as users expressed concerns regarding LayerZero’s verifier model.
In response to broader industry losses—including the KelpDAO hack and the Drift Protocol breach—major DeFi players have begun restructuring their presence on low-activity networks, or ‘ghost chains’. Aave is targeting the shutdown of V3 lending deployments across six networks, while LayerZero has removed support for 32 chains. These strategic exits aim to mitigate security risks, specifically addressing vulnerabilities like single-verifier configurations that facilitate cross-chain message spoofing.
Entities
LayerZero · Aave · KelpDAO · Chainlink · Drift Protocol
Timeline
-
11 days ago
[TECHNOLOGY] 2 sourcesAave and LayerZero exit low-activity ghost chains to mitigate DeFi risksAave and LayerZero are exiting low-activity ‘ghost chains’ to combat DeFi security risks following $1.3 billion in exploits during H2 2026.
-
24 days ago
[TECHNOLOGY] 3 sourcesKelpDAO exploit triggers $15B DeFi migration and Aave asset declineA major KelpDAO bridge exploit by North Korean hackers has caused Aave's TVL to drop 43% and triggered a $15 billion migration of DeFi assets from LayerZero to Chainlink.
Sources
ambcrypto.com · detlionblood32.wordpress.com