Aave and LayerZero have launched coordinated efforts to shut down support for low-activity blockchain networks, citing security concerns following a series of major infrastructure attacks in 2026.
Aave announced in July that it would discontinue V3 lending deployments across six networks—including Sonic, Scroll, and Aptos—based on a new risk framework that enforces strict activity thresholds and requires a minimum of three verifiers for cross-chain transactions. LayerZero simultaneously announced the removal of support for 32 chains, including Arbitrum Nova and Gnosis Chain.
Infrastructure Attacks Drive the Response
The moves follow two major exploits in the second half of 2026. DeFi protocols suffered $1.3 billion in losses during that period, with over 40 percent stemming from the KelpDAO hack ($292 million) and the Drift Protocol breach ($285 million). Both attacks exploited operational and infrastructure security flaws rather than typical smart contract vulnerabilities.
The KelpDAO incident occurred because the protocol relied on a single verifier (1-of-1 configuration) to authorize cross-chain messages. A second verifier could have prevented the fraudulent transfer, according to industry observers.
Infrastructure attacks, including cross-chain message spoofing, ranked among the largest attack vectors for stolen cryptocurrency in the first half of 2026. Low-activity networks disproportionately rely on risky 1-of-1 verifier configurations, making them potential weak links that could trigger contagion across the broader network.
Split Opinions on Effectiveness
Industry experts are divided on whether the purge will meaningfully reduce future exploits. Tim Sun, a senior researcher at HashKey Group, noted that ghost chains tend to have higher attack vulnerabilities and that concentrating node operations on fewer providers degrades security redundancy. He warned that reduced economic incentives on inactive chains can prompt node operators to exit, amplifying risks.
However, Joe Armstrong, Growth and Partnerships Director at node operator LinkPool, argued the purge addresses only a shallow category of risk. He contended that most losses stem from off-chain signing and bridging exploits that remain untouched, and cautioned that the hurried timeline could have unintended consequences for emerging blockchain projects seeking infrastructure support.
Vladimir Tikhomirov, co-founder of DeFi infrastructure firm Algebra, countered that removing chains that no longer meet safety standards represents necessary industry maturation that reduces the attack surface.
Market Impact and Recovery
LayerZero's bridge transfer volume declined from nearly $4 billion to $1 billion following the KelpDAO fallout before recovering to $2 billion. Over $15 billion migrated to rival Chainlink CCIP during the period. LayerZero maintained higher transfer volumes than Chainlink despite the migration, though whether the protocol will return to pre-exploit levels near $4 billion remains uncertain.
The infrastructure attacks have prompted protocols including Aave to reassess expansion strategies. The emphasis on selective deployment comes as the industry acknowledges that broad multi-chain support, once viewed as a growth indicator, now represents an operational and security liability.


