Scan to download
BTC $79,086.74 -2.81%
ETH $2,223.31 -3.29%
BNB $673.10 -1.15%
XRP $1.43 -7.00%
SOL $89.53 -4.12%
TRX $0.3519 -0.75%
DOGE $0.1130 -2.86%
ADA $0.2609 -5.28%
BCH $426.07 -2.77%
LINK $10.07 -5.68%
HYPE $44.82 +1.00%
AAVE $93.10 -6.87%
SUI $1.10 -9.07%
XLM $0.1545 -6.75%
ZEC $522.37 -1.97%
BTC $79,086.74 -2.81%
ETH $2,223.31 -3.29%
BNB $673.10 -1.15%
XRP $1.43 -7.00%
SOL $89.53 -4.12%
TRX $0.3519 -0.75%
DOGE $0.1130 -2.86%
ADA $0.2609 -5.28%
BCH $426.07 -2.77%
LINK $10.07 -5.68%
HYPE $44.82 +1.00%
AAVE $93.10 -6.87%
SUI $1.10 -9.07%
XLM $0.1545 -6.75%
ZEC $522.37 -1.97%

layerzero

After being attacked, KelpDAO has seen multiple protocols abandon LayerZero, with $4 billion in assets migrated to Chainlink CCIP

After KelpDAO was attacked, resulting in a loss of $292 million, the industry's scrutiny of the security of cross-chain infrastructure has intensified. Approximately $4 billion in assets have completed or are in the process of migrating from LayerZero to Chainlink's Cross-Chain Interoperability Protocol (CCIP). The DeFi protocol Lombard is the latest project to join this migration trend. The protocol announced it would discontinue the use of LayerZero and migrate over $1 billion in Bitcoin-backed assets to Chainlink CCIP, stating that this decision stemmed from a comprehensive internal security review following the April attack incident.Lombard issues two types of Bitcoin-backed tokens—LBTC and BTC.b—and will prioritize the migration of assets on chains such as Solana, Etherlink, Berachain, Corn, and TAC, while terminating the use of LayerZero on Morph and Swell. Lombard stated that the reason for choosing CCIP is its independent node operators, built-in rate limiting mechanisms, and audited infrastructure. Additionally, the protocol will adopt Chainlink's cross-chain token standard to facilitate asset cross-chain circulation through a burn-and-mint model.Previously, Kelp DAO, Solv Protocol, Re, and the cryptocurrency exchange Kraken have all completed similar migrations, with these projects collectively transferring approximately $4 billion in assets. Chainlink Labs Chief Business Officer Johann Eid stated, "We are witnessing a continued wave of risk-averse migration within the industry."

LayerZero has been reported to have used multi-signature wallets to trade Meme coins, and the default library contract upgrade mechanism poses risks

According to market news, LayerZero Labs co-founder and CEO Bryan Pellegrino had a heated debate with security researchers today in the ETHSecurity Community Telegram group. The core controversy includes: since LayerZero Labs can immediately upgrade a default library contract without a time limit to forge messages (similar to the case where rsETH was hacked), the LZ OFT, valued at over $3 billion, is recently at risk of being stolen; researcher Banteg pointed out that mainstream projects like Ethena and EtherFi were still using this default library contract weeks ago, and currently, there is still $178 million worth exposed to risk, with these funds coming from projects that are still using the default library.On-chain data shows that LayerZero Labs multi-signature signers participated in non-multi-signature activities such as meme coin trading, DEX exchanges, and cross-chain bridging, which means that the multi-signature keys in the formal environment were connected to websites, increasing phishing risks. Regarding the multi-signature signers of LayerZero using production environment keys for trading activities, Bryan confirmed that the related transactions were completed by members of the multi-signature team, but denied that it was "meme coin trading," explaining it as "testing PEPE on the LZ OFT token standard," and stated that the involved member has been removed. Bryan also suggested that project parties "directly fix configurations" instead of using default configurations to reduce risks. Banteg subsequently tagged a long list of LayerZero users still using the default library contract, pointing out that these projects should migrate to fixed configurations as soon as possible.
app_icon
ChainCatcher Building the Web3 world with innovations.