# Kelp DAO Shifts to Chainlink After $292 Million Bridge Exploit

**Published:** 2026-04-22T07:00:00.000Z  
**Topic:** Dao Crypto  
**Sentiment:** neutral  
**Publisher:** TrendWatcher — https://www.trendwatcher.in/article/a9412d3f-43eb-4b54-a562-2418f28b4d5b

Kelp DAO is migrating to Chainlink CCIP following a $292 million exploit of its cross-chain bridge, highlighting ongoing security risks in DeFi protocols.

The decentralized finance (DeFi) sector has faced a turbulent 2026, highlighted by an April 18 exploit of Kelp DAO that resulted in the theft of approximately 116,500 rsETH, valued at roughly $292 million [1]. The attack, which targeted the protocol's cross-chain bridge, stands as one of the largest security breaches of the year and has prompted a significant shift in the project's technical infrastructure [1].

**Key takeaways**
* The April 18 Kelp DAO exploit resulted in the loss of approximately $292 million in rsETH [1].
* Investigations by LayerZero, Mandiant, and CrowdStrike attributed the breach to social engineering and the harvesting of session keys starting on March 6 [1].
* Kelp DAO is migrating its cross-chain operations from LayerZero to Chainlink’s Cross-Chain Interoperability Protocol (CCIP) to enhance security [2].
* North Korea-linked actors were responsible for 76% of global crypto hack losses in the first four months of 2026 [1].

## Architectural vulnerabilities and the shift to CCIP
Following the breach, Kelp DAO announced on May 5 that it would replace its existing LayerZero infrastructure with Chainlink’s CCIP [2]. The protocol’s leadership maintains that the root cause of the incident was the underlying infrastructure of the bridge rather than internal protocol errors [2]. Independent firms, including SEAL 911 and Chainalysis, reportedly traced the breach to LayerZero’s systems, which the project claims led to total ecosystem losses exceeding $300 million [2]. 

The migration to Chainlink is intended to address the architectural risks exposed by the attack [2]. Unlike the previous setup, Chainlink CCIP requires consensus from 16 independent node operators for every transaction, a design intended to eliminate the single-point-of-failure risks that allowed the April exploit to occur [2]. Technical preparations for this transition are already underway, with new CCIP-compatible contracts appearing in the project's public repositories [2].

## The broader DeFi security landscape
The Kelp DAO incident is part of a wider trend of DeFi protocols struggling with structural weaknesses in bridges and administrative systems [1]. In the first five months of 2026, over $840 million has been lost to such hacks, with April alone accounting for more than $600 million in stolen funds [1]. Experts note that attackers are increasingly using social engineering and AI-assisted reconnaissance to identify vulnerabilities in smart contracts and administrative keys [1].

## Why it matters
The scale of the Kelp DAO exploit triggered a massive $6.2 billion wave of withdrawals from the lending platform Aave, necessitating a coordinated industry recovery effort known as "DeFi United" to backstop the resulting bad debt [1]. The incident underscores a growing consensus among security professionals that cybersecurity in the blockchain space is a "full-stack problem" that requires addressing human processes alongside technical code audits [1]. As protocols like Kelp DAO move toward more robust, multi-party validation systems, the industry continues to grapple with the reality that cross-chain complexity remains a primary target for sophisticated state-linked actors [1].

## Sources
1. Decrypt — [Why DeFi Keeps Losing Millions to Exploits](https://decrypt.co/368591/why-defi-keeps-losing-millions-to-exploits)
2. Crowdfund Insider — [DeFi Protocol Kelp DAO Pivots to Chainlink CCIP for Stronger Cross-Chain Security](https://www.crowdfundinsider.com/2026/05/277512-defi-protocol-kelp-dao-pivots-to-chainlink-ccip-for-stronger-cross-chain-security/)

---
Cite as: TrendWatcher, "Kelp DAO Shifts to Chainlink After $292 Million Bridge Exploit", https://www.trendwatcher.in/article/a9412d3f-43eb-4b54-a562-2418f28b4d5b
