AAVE, LayerZero axe ghost chains – But DeFi’s real problems run much deeper
Ghost chains have become the weakest links and low-cost attack venues for cross-chain protocols
Industry cleansing or hurried retreat? Experts split on LayerZero’s ghost chain purge.
DeFi exploits hit $1.3B in H2 2026, but over 40% of the losses came from two incidents: KelpDAO ($292M) and Drift Protocol ($285M). The two breaches involved operational and infrastructure security flaws, not typical smart contract bugs.
The reaction and mitigation have been swift, as lending protocol Aave and interoperability player LayerZero shift focus to one key thing: “ghost chains.”
For Aave, V3 lending deployments across six networks, including Sonic, Scroll, and Aptos, were targeted for shutdown for ‘low activity.’ LayerZero, which powered KelpDAO’s compromised Decentralized Verification Network (DVN), axed support for 32 chains, including Arbitrum Nova and Gnosis Chain.
This raises key questions: How risky are the so-called ghost chains? And is the purge enough to reduce the DeFi exploits?
KelpDAO fallout: Are ghost chains a DeFi threat?
In July, about three months after the KelpDAO hack, Aave announced its pruning exercise targeting six chains based on its new risk framework.
The framework had strict chain activity and revenue thresholds. Additionally, the lending protocol sought a minimum of three verifiers for bridging requirements.
For the unfamiliar, the KelpDAO exploit happened because it had only a single verifier (1-of-1 DVN) signing off the cross-chain message. Having two or more verifiers could have allowed another party to catch the dubious transfer.
In the same month, LayerZero announced a similar purge.
So, how do ghost chains or so-called “low-activity” networks targeted by LayerZero and Aave fit into these attacks?
Infrastructure attacks, including cross-chain message spoofing, have become one of the largest attack vectors for stolen crypto in H1 2026.

Most low-activity networks tend to run the basic but risky 1-of-1 DVN configurations. Since cross-chain protocol attacks can trigger a contagion from one network to another, ghost chains have been flagged as one of the weakest links.
A similar stance was echoed by Tim Sun, a senior researcher at digital asset financial services firm HashKey Group. He told AMBCrypto that,
Cross-chain protocols have always been one of the areas with the most concentrated DeFi security risks. Ghost chains also tend to have relatively higher attack costs and vulnerabilities, with the previous KelpDAO incident being a typical example.
Sun added that node operators can amplify the risks of ghost chains. For inactive chains, node operation costs remain fixed, yet fees and economic incentives that nodes can earn decrease.
This can trigger exits, concentrating node operations to a small number of providers. In such a scenario, Sun warned that the risk of primary network failure increases and security redundancy degrades.
Notably, Nethermind, one of the node operators on LayerZero, ditched it for rival cross-chain player Chainlink CCIP.
Impact of the ghost chain purge by LayerZero and Aave
That said, whether the pruning exercise will reduce infrastructure attacks or stolen crypto value remains debatable.
For Joe Armstrong, Growth and Partnerships Director at node operator LinkPool, the ghost chains purge is less effective in improving DeFi security. According to him, most of the losses come from off-chain signing and bridging exploits.
The purge closes a category of risk (obscure inactive chains) that was easy to reach and shallow, but it leaves the category that produces the largest losses untouched.
LinkPool runs nodes for seven of the 32 chains LayerZero has axed out. According to Armstrong, the pruning exercise was done hurriedly and could have unintended consequences. Especially for new upstart chains.
Every time support is withdrawn at short notice, operators get more conservative about backing anything speculative. This makes it harder for the next chain to secure infrastructure before it has users, which is exactly when it needs it most.
In contrast, HashKey Group’s Sun billed the purge as a net positive for the segment.
In the long run, this is a necessary stage for the industry to cleanse itself. From a security perspective, this can also effectively reduce the attack surface of DeFi.
Vladimir Tikhomirov, co-founder of Alegebra, a DeFi infrastructure firm, also supported the purge, adding that,
The problem with ghost chains is that, as activity on them goes down, so does the overall level of security. Getting rid of chains that no longer meet growing safety demands is actually a step forward.
Will DeFi user trust improve?
Previously, a protocol with wide support across as many chains could be read as a growth story. But it comes with extra commitment (constant monitoring), operational costs, and sometimes expensive attack surfaces, especially from low-activity chains.
Now, the ‘deploy everywhere’ DeFi is a risk factor.
As LayerZero scales back support for several networks, over $15B has migrated to rival Chainlink. The protocol’s bridge transfer volume declined by 4X from nearly $4B to $1B before recovering to $2B.

Despite the migration amid KelpDAO fallout, LayerZero still had higher transfer volumes than Chainlink. It remains to be seen whether LayerZero’s activity will hit pre-KelpDAO exploit levels near $4B.
Overall, the DeFi hacks this year have triggered a much-needed reckoning. Now protocols like Aave are reconsidering expansion amid rising threats targeting the weakest links: ghost chains.
Final Summary
- Infrastructure attacks, led by KelpDAO and Drift hacks, accounted for +40% of crypto losses in H1 2026
- Aave and LayerZero are targeting ghost chains as a mitigation strategy, but analysts are split on its potential impact.