Crypto custody firm BitGo is shifting about $7.3bn of Wrapped Bitcoin (wBTC) from LayerZero to Chainlink's Cross-Chain Interoperability Protocol (CCIP), marking the biggest transfer yet in a migration wave that has moved nearly $14.6bn of institutional crypto assets away from LayerZero since a high-profile hack in April.
BitGo's Move to Chainlink Shows LayerZero Still Hasn't Outrun Kelp Hack
BitGo said on 4 Aug that it will move wBTC from LayerZero to Chainlink's CCIP, citing security as a priority. CCIP will become the exclusive cross-chain provider for wBTC and, by extension, for all future assets issued by BitGo. "BitGo has long been built around a simple principle: security comes first," CEO Mike Belshe said in a statement.
The company will pair CCIP's messaging layer with Chainlink's Cross-Chain Token standard, which lets BitGo keep direct control over contracts, transfer limits and rate limits rather than handing that authority to Chainlink.
BitGo is following the lead of roughly half-dozen firms before it. Kraken made a similar transition in May, followed by Mantle, Lombard, Solv Protocol, Virtuals, Re and Aave. With wBTC added, institutional crypto is concentrating a meaningful share of its cross-chain infrastructure onto a single provider.
LayerZero reverses course
The migrations followed a three-week security crisis that began in April, when LayerZero – which provides infrastructure for transferring tokens and data between blockchains – came under scrutiny over the safeguards protecting high-value assets.
Attackers linked to North Korea's Lazarus Group stole about $292mn on 18 Apr from the rsETH bridge belonging to Kelp DAO, a liquid restaking protocol, using compromised infrastructure rather than a flaw in Kelp's smart contracts.
LayerZero's initial postmortem, published the next day, pinned the exploit on Kelp's choice to run a single-verifier setup rather than LayerZero's recommended multi-verifier model. Kelp disputed that framing publicly in May, saying LayerZero staff had approved the configuration and never flagged it as risky, and that the setup wasn't unique to Kelp: LayerZero's own data showed 47% of active contracts on the network were running the same single-verifier arrangement.
On 9 May, LayerZero changed its position over the incident. The company said it had "made a mistake" allowing its verification network to secure high-value assets in that configuration, banned the setup outright and moved every integration onto stricter multi-verifier defaults.
Security fears drive shift
That admission, not the hack itself, is what triggered the exodus that followed: LayerZero had conceded that nearly half its integrations shared Kelp's exposure, and that its own staff had signed off on the configuration.
No amount of reconfiguring a single client's own setup could fix a problem the network operator had just admitted was structural. Chainlink's architecture is said to be built around an independently coded Risk Management Network, designed to avoid the single-verifier failure mode that cost the Kelp protocol $292mn.
The migration creates a different kind of risk, however: concentration. A growing share of the industry's most security-sensitive assets now depends on one provider continuing to operate reliably, rather than being distributed across several systems where the impact of any failure might be contained.