Nethermind Drops LayerZero Verifier Role, Moves to Chainlink Network
Ethereum infrastructure firm Nethermind has exited its position as a Decentralized Verifier Network (DVN) operator on LayerZero's cross-chain messaging protocol and joined Chainlink as a node operator, the company announced August 19, 2026. The move comes four months after a $292 million exploit on LayerZero that combined two compounding failures: a 1-of-1 DVN configuration used by KelpDAO and a breach of LayerZero's own internal RPC infrastructure.
Nethermind will now help secure two Chainlink products: the Cross-Chain Interoperability Protocol (CCIP), which validates transactions moving assets between blockchains and carries arbitrary cross-chain messages, and Chainlink's Data Feeds, which supply price information to decentralized finance applications.
Nethermind's previous LayerZero DVN role was publicly verifiable on Ethereum at contract address 0xa59BA433ac34D2927232918Ef5B2eaAfcF130BA5. The company framed the transition as "securing the next era of capital markets" in its announcement blog post. Adding competitive texture to the move: Chainlink itself was already operating as a DVN on LayerZero alongside Nethermind as of early 2026, meaning Nethermind is departing a network where the two firms were co-participants to join Chainlink's own infrastructure directly.
The KelpDAO incident looms over the shift. On April 18, 2026, an attacker forged a cross-chain message on LayerZero that appeared to originate from KelpDAO's Unichain deployment. The message passed through a single compromised verifier operating in what is called a 1-of-1 configuration, meaning just one entity had to approve the transaction for it to execute. The attacker had spent weeks socially engineering a LayerZero developer starting March 6, 2026, eventually gaining access to internal infrastructure, harvesting session keys from LayerZero's RPC cloud environment, and poisoning the network's RPC nodes to fake DVN attestations. The result was 116,500 rsETH drained from KelpDAO's Ethereum escrow contract, valued at roughly $292 million. A second attempted drain of approximately $100 million was blocked 46 minutes later. Security researchers and investigators have attributed the attack to North Korea's Lazarus Group (also tracked as TraderTraitor and UNC4899).
LayerZero and KelpDAO publicly disputed responsibility. KelpDAO stated that "LayerZero's own infrastructure was exploited, resulting in $300M in losses across DeFi" (KelpDAO's rounded figure; contemporaneous reports put the loss at approximately $292 million). LayerZero Labs eventually acknowledged it "made a mistake by allowing our DVN to act as a 1/1 DVN for high-value transactions."
Since then, LayerZero has announced it is moving all default configurations to 5-of-5 DVN setups where possible, with a minimum of 3-of-3 on any chain where fewer DVNs are available, requiring multiple independent operators to sign off on any high-value cross-chain message before it executes. That remediation has drawn skepticism from parts of the developer community, with critics arguing that raising verifier counts will not stop the next major exploit if underlying architectural trust assumptions and infrastructure security remain unaddressed.
The fallout extended well beyond KelpDAO. Solv Protocol moved more than $700 million in tokenized Bitcoin infrastructure away from LayerZero, and KelpDAO announced plans to migrate its rsETH bridge entirely to Chainlink CCIP.
Nethermind's departure adds institutional weight to that trend. The London-based firm runs the second most widely used Ethereum execution client, holding roughly 23% of Ethereum node market share. Its founder, Tomasz Kajetan Stańczak, also served as co-executive director of the Ethereum Foundation. In June 2026, Nethermind completed a proof-of-concept with UBS Bank demonstrating that public Ethereum mainnet can meet the compliance and operational requirements of regulated financial institutions. That institutional positioning makes its choice of Chainlink over LayerZero a meaningful signal for developers evaluating which cross-chain infrastructure to build on.
Chainlink CCIP currently connects more than 70 blockchains and processed over $18 billion in cross-chain transfer volume in Q1 2026 alone, a 78% increase from the previous quarter and 319% higher than the same period a year earlier. As of Q1 2026, the protocol was the only cross-chain platform to hold SOC 2 Type 2, SOC 2 Type 1, and ISO/IEC 27001:2022 security certifications, all verified by Deloitte & Touche LLP. Sixteen independent, security-reviewed node operators currently secure the network; Nethermind is joining that group.
For developers in South Asia and Africa, the implications are practical. India has one of the largest concentrations of blockchain developers globally, many building cross-chain applications on LayerZero's Omnichain Fungible Token (OFT) standard. The KelpDAO exploit should be treated as a direct case study in configuration risk: protocols that used default LayerZero settings with minimal verifier counts carry an exploited, documented configuration risk unless those settings have since been manually upgraded.
Chainlink CCIP's SOC 2 certifications carry added weight for teams in India building products that intersect with institutions regulated by SEBI or the RBI.
In Africa, where DeFi hubs in Nigeria, Kenya, Ghana, and South Africa have adopted cross-chain tooling rapidly for stablecoin transfers, remittances, and real-world asset tokenization, LayerZero retains developer mindshare due to its relatively low barrier to entry. But the post-exploit requirement for multi-verifier configurations adds operational overhead that smaller, under-resourced teams may find difficult to manage. Chainlink CCIP's integration with Swift, which connects more than 11,500 financial institutions globally, is also relevant to African fintech builders exploring cross-border payment corridors.
On-chain and market data reflect the credibility gap between the two networks. LINK, Chainlink's native token, was trading at approximately $8.38 on August 19 with a market cap near $5.93 billion and 24-hour trading volume around $305 million. ZRO, LayerZero's token, was trading at approximately $1.47 per CoinGecko, with a market cap near $304 million.
Whether LayerZero's revised security defaults and remaining operator network can rebuild institutional confidence will determine whether this departure is an outlier or part of a longer consolidation toward CCIP.