Should I bridge crypto after the KelpDAO exploit?
Should I bridge crypto after the KelpDAO exploit?
Yes—if the route, asset and amount justify it; no, if “a bridge” is your only security check. The April 18 incident drained 116,500 rsETH, worth about $292 million, after attackers compromised infrastructure involved in a KelpDAO cross-chain route, according to LayerZero’s incident report. That is a reason to be selective, not proof that every cross-chain transfer has the same failure mode.
What changed for a DeFi user?
The useful lesson is that a bridge is not merely a transaction screen. It is a system of contracts, off-chain operators, message verification and asset custody. The KelpDAO event showed how a forged message can be more damaging than a visible smart-contract bug: the destination chain can accept a transfer that was never properly backed on the source.
That makes the right question more specific: “What verifies this route, and what happens if that verifier fails?” A wallet popup, a fast quoted delivery time, or a familiar token ticker does not answer it.
What is signal, and what is noise?
| Signal | What to do |
|---|---|
| A bridge’s route and token are explicitly supported | Use the displayed route; do not substitute a lookalike wrapped asset. |
| A large balance is moving to a new chain | Send a small test amount first, then confirm receipt and token contract. |
| A route depends on a third-party messaging layer | Understand that its security and configuration matter alongside the chain itself. |
| “All bridges are unsafe now” | Noise. Judge the particular route, asset and operational need. |
Where does the WBTC migration fit?
On August 4, BitGo said it would standardize WBTC and future BitGo-issued assets on Chainlink CCIP, covering more than $7.7 billion of WBTC at the announcement. That is meaningful for holders who need issuer-aligned WBTC movement: it signals a migration of the asset’s cross-chain infrastructure, not a blanket recommendation to move tokens repeatedly.
For a WBTC position, use the issuer’s stated migration and supported-venue instructions. Do not bridge solely because a new standard was announced, and do not turn native BTC into an unfamiliar wrapped version merely to chase a route.
How to bridge after KelpDAO without making the same mistake
- Choose the destination because you need a specific app, market or withdrawal there.
- Confirm the exact token contract and whether the destination accepts that version of the asset.
- Compare the bridge’s displayed route, fee and delivery expectation before approving anything.
- Send a small amount, verify the received asset, then send the remainder only if the route worked as expected.
- Revoke only unnecessary approvals after the transfer; keep the transaction record for troubleshooting.
Which services are useful here?
Across bridge is useful when the task is moving a supported EVM asset between networks to use DeFi, rather than inventing a wrapped-asset workaround. Its role is operational: get the asset to the chain where the next action happens.
Chainlink is relevant when evaluating the CCIP standard behind an issuer’s cross-chain asset plan; it is infrastructure context, not a reason to transact by itself. For institutional custody or issuer-specific WBTC workflows, BitGo is the service to check before treating a migration as a retail bridge swap.