Crypto tasks with greater than $3 billion in complete worth locked have migrated their cross-chain infrastructure to Chainlink’s Cross-Chain Interoperability Protocol (CCIP) following a $292 million exploit at KelpDAO, which heightened scrutiny of bridge safety throughout decentralized finance.
Chainlink confirmed the migration wave, saying 4 protocols, together with KelpDAO, Solv Protocol, Re, and Tydro, had begun decommissioning legacy oracles and bridge methods in favor of CCIP.
The shift has additionally fed into LINK’s market efficiency. CryptoSlate knowledge exhibits the token rose 15% to $10.52, its highest stage since January, as merchants responded to the acceleration in CCIP adoption.
Blockchain analytics agency Santiment stated the rally got here alongside a tightening in LINK’s out there provide on exchanges. In accordance with the agency, LINK’s change reserves fell by 13.5 million LINK over 5 weeks, representing greater than 10.5% of the exchange-held provide recorded in early April.


The value transfer displays a broader reassessment of Chainlink’s function in crypto infrastructure. After years of being recognized primarily for worth feeds and oracle companies, the community is now changing into a direct beneficiary of DeFi’s seek for safer cross-chain rails.
Why are DeFi protocols embracing Chainlink’s CCIP?
Cross-chain bridges enable tokens, NFTs, and knowledge to maneuver between in any other case separate blockchain networks. This implies these platforms let customers shift liquidity between ecosystems, reminiscent of shifting property from Ethereum to Solana, with out counting on a centralized change.
That operate has change into important as DeFi has unfold throughout a number of blockchains. Lending markets, staking tokens, stablecoins, and tokenized property more and more rely upon infrastructure that may transfer worth between networks with out fragmenting liquidity or locking customers right into a single chain.
Nevertheless, bridges have additionally change into one in every of crypto’s most ceaselessly attacked items of infrastructure. It is because they usually depend on complicated verification methods and maintain giant swimming pools of locked property, making them engaging targets for hackers.
Chainalysis has described cross-chain bridges as one of many blockchain business’s main safety dangers. As of 2022, greater than $2 billion had been stolen throughout 13 bridge hacks, with North Korean-linked teams among the many most energetic attackers.
That historical past has pushed DeFi protocols towards infrastructure that may provide extra standardized safety controls. Chainlink’s CCIP, which launched on mainnet in July 2023, has change into one of many foremost beneficiaries of that shift.
CCIP makes use of Chainlink’s decentralized oracle networks, the identical infrastructure behind the info feeds that safe giant components of DeFi. Chainlink says these networks now embrace greater than 2,000 decentralized oracle networks in manufacturing, securing over $110 billion in worth and powering greater than 70% of DeFi.
In contrast to many conventional bridges, which may rely upon a slender set of validators or verification pathways, CCIP is designed to transmit each knowledge and token worth throughout chains by means of Chainlink’s oracle infrastructure.
That offers protocols a method to transfer property whereas decreasing reliance on bespoke bridge designs.
For protocols managing a whole bunch of hundreds of thousands of {dollars} in property, cross-chain infrastructure is now being evaluated much less as back-end plumbing and extra as a core a part of threat administration.
LayerZero makes an attempt to comprise the fallout
In the meantime, the migration wave has put LayerZero, the cross-chain platform beforehand utilized by KelpDAO, below stress to clarify its function within the $292 million breach.
LayerZero issued an apology on Might 9, about three weeks after the April 18 breach. The corporate acknowledged that its post-exploit communication had fallen quick and conceded that its safety mannequin allowed a high-value software to function with inadequate safeguards.
LayerZero had initially maintained that its infrastructure labored as designed and that duty sat with the applying configuration.
Nevertheless, its more moderen feedback struck a unique tone, acknowledging that it ought to have exercised stronger oversight over how its decentralized verifier community was used.
The corporate stated it “made a mistake” by permitting its Decentralized Verifier Networks (DVNs) to operate as the only real verifier for high-value cross-chain transactions with out ample guardrails.
It famous:
“We did not police what our DVN was securing, which created a threat we merely did not see. We personal that.”
The admission goes to the center of the dispute. LayerZero’s structure offers software builders the pliability to configure verification as they see match. That customizability has lengthy been a part of the protocol’s enchantment, significantly for groups looking for extra management over their cross-chain safety assumptions.
The KelpDAO exploit has uncovered the weak spot of that strategy when groups function with a too-narrow verification setup. If an software relies on a single verifier, a compromise in that layer can change into a direct risk to consumer funds.
In the meantime, LayerZero additionally disclosed a beforehand unreported incident from three years in the past involving one in every of its multisig signers.
The corporate stated the signer mistakenly used LayerZero {hardware} to conduct a private commerce. The signer was eliminated, wallets had been rotated, and LayerZero later moved to a custom-built multisig framework.
The disclosure appeared meant to point out that the protocol had addressed earlier inside safety lapses. Nevertheless, it additionally added one other layer of scrutiny at a second when purchasers had been already reassessing their publicity.
LayerZero stated the KelpDAO exploit affected solely a single software, representing 0.14% of community purposes and roughly 0.36% of complete worth on the protocol. It additionally stated no different software was affected.
That protection leaves LayerZero with a slender however tough argument. The corporate is attempting to point out that the exploit was remoted whereas additionally admitting that the configuration mustn’t have been allowed to safe a lot worth with out stronger oversight.
Can LayerZero restore institutional confidence?
The central query now’s whether or not LayerZero’s apology and technical clarification can sluggish the migration of protocols towards Chainlink.
Tom Wan, head of knowledge at Entropy Advisors, questioned whether or not the injury to institutional confidence had already been completed. He wrote
“Can an apology cease their purchasers from leaving to Chainlink, or is that this just the start?”
LayerZero has tried to reply that concern with utilization knowledge. The corporate stated greater than $9 billion had moved by means of its infrastructure because the April assault, a determine meant to point out that customers and purposes proceed to depend on the protocol regardless of the KelpDAO incident.
Wan additionally famous that a number of main property, together with USDe, WBTC, and weETH, stay energetic on LayerZero.
That continued utilization suggests the protocol has not suffered a full lack of confidence, whilst a number of distinguished tasks shift components of their cross-chain stack elsewhere.
LayerZero additionally retains defenders who argue that the protocol’s flexibility stays its core benefit.
In that view, customizability shouldn’t be a flaw by itself. The chance arises when software groups fail to align their safety configuration with the amount of capital flowing by means of their methods.
Lorenzo Romagnoli, co-founder of USDT0, stated LayerZero’s mannequin requires asset issuers to take safety critically from the beginning. USDT0, the biggest asset on the LayerZero community, has moved $4 billion throughout chains with out incident.
Romagnoli stated:
“LayerZero is the golden commonplace for cross-chain interoperability due to its excessive stage of customizability. Sadly, this implies software homeowners want to take a position critical sources to match the safety commonplace that the capital shifting by means of our rails calls for.”
Romagnoli stated USDT0 operates its personal proprietary veto-powered DVN, with invariance checks tailor-made to its particular threat profile. He argued that the protocol remained unaffected as a result of it handled safety as a part of the product, somewhat than a function inherited robotically from the underlying rails.
That protection captures the broader debate now dealing with cross-chain infrastructure. Protocols need flexibility, however in addition they want defaults and guardrails sturdy sufficient to guard giant swimming pools of consumer capital. The KelpDAO exploit has made that trade-off tougher to disregard.
For Chainlink, the migration wave strengthens CCIP’s place as a security-focused cross-chain commonplace, as DeFi groups reassess vendor threat.
For LayerZero, the problem is to show that its customizable mannequin can meet institutional expectations with out exposing high-value purposes to weak configurations.









