KETJU Research

← The Register

other

LayerZero V2

Rejected
Max sleeve
Reviewed
2026-08-17 · v1
Next review
2026-11-17
Research basis
Individual research
Chains
Ethereum · sovereign

Rejected venues wait the longest for re-review; a rejection has to earn another look before the scheduled date.

REJECTED AS A DEPENDENCY, ON A REALIZED INFRASTRUCTURE COMPROMISE. LayerZero is not a bridge itself; it is a messaging layer other protocols build bridges and omnichain tokens on, so its $6.7B tracked figure likely aggregates value already counted under downstream integrators like Stargate and USDT0 rather than value LayerZero itself custodies — an entity-resolution question this registry has not yet resolved. Security per integration is configurable: an app picks which Decentralized Verifier Network (DVN) operators must attest to a message, from a single DVN up to a larger set. On 2026-04-18, attackers compromised LayerZero Labs’ own operational infrastructure — two internal nodes on separate clusters — to forge attestation data and steal about $292M (116,500 rsETH) from Kelp DAO’s OFT bridge, which used a 1-of-1 configuration trusting only LayerZero Labs’ own DVN. This was not a smart-contract bug; it was proof that LayerZero Labs’ own infrastructure is a real, exploited single point of failure for any integration that does not add independent verification, which is the default posture for a large share of real deployments.

The research file

Mechanism

LayerZero is an omnichain messaging protocol. Its Omnichain Fungible Token (OFT) standard lets a token burn on a source chain and mint on a destination chain via LayerZero message passing, rather than locking into a shared liquidity pool. Stargate, LayerZero Labs’ own flagship bridge (spun into a DAO, later reacquired for $110M), is the largest OFT application and pools liquidity across chains. LayerZero’s Endpoint contracts pass messages; they do not themselves custody the pooled value that downstream applications hold, which is why counting LayerZero’s TVL alongside Stargate’s or USDT0’s risks double-counting the same underlying value.

Control and the DVN trust model

Each application chooses X required plus Y-of-N optional DVNs that must attest to a message before delivery. About 35 DVN operators exist, including Google Cloud, Chainlink, Polyhedra Network, and LayerZero Labs itself, but the default and most common configuration for many integrators is a single DVN run by LayerZero Labs — meaning the practical trust assumption for most real deployments reduces to trusting LayerZero Labs’ own infrastructure, not a decentralized set. Endpoint contracts are stated to be immutable; Message Library contracts, which handle encoding and verification orchestration, are versioned and upgradeable, and this review could not confirm exactly who holds upgrade authority over them.

The April 2026 incident

Attackers, attributed with high confidence to Lazarus Group, breached two independent internal nodes LayerZero Labs operated on separate clusters, replaced their software to feed forged attestation data, and simultaneously DDoS’d a third-party RPC node to force reliance on the compromised internal ones. Kelp DAO’s rsETH OFT deployment used a 1-of-1 DVN configuration — LayerZero Labs’ DVN only — so the forged attestation was accepted without cross-check, and about $292M was stolen; a second attempt near $95M was blocked when Kelp paused contracts post-detection. LayerZero and Kelp have publicly disputed responsibility for the 1-of-1 configuration choice; Kelp is now migrating rsETH off the OFT standard entirely. LayerZero states the compromised nodes have been replaced and now recommends multi-DVN setups, but the incident itself is not in dispute.

Exit and dependency framing

There is no direct deposit or withdrawal product here to test for exit liquidity — LayerZero should be modeled as a dependency, in the sense of Ketju’s own object taxonomy for bridge, oracle, and curator risk that other positions depend on, not as a directly allocable position. Any approved Ketju position that moves through a LayerZero-secured OFT or Stargate pool inherits that specific integration’s DVN configuration as a control dependency, and the Kelp incident shows this must be checked per integration, per configuration — a multi-DVN integration and a 1-of-1 integration do not carry the same risk despite sharing the LayerZero name.

Comparison

Wormhole uses 19 Guardian validators and had its own major 2022 exploit (a smart-contract signature-verification bug, not an infrastructure compromise, $325M). Axelar uses a proof-of-stake validator set with delegated staking and slashing. Chainlink CCIP layers an independent Risk Management Network on top of its oracle network specifically so a single compromised component cannot forge a message without a second, structurally separate system flagging it — a design that does not depend on each integrator opting into extra verifiers the way LayerZero’s configurable DVN model does. None of these alternatives are approved by this review; each would need its own memo, and USDT0 — a LayerZero OFT deployment — is reviewed separately in this registry.

Sources

The claims above trace to these. Where a number could not be independently verified, the thesis says so.

Inherited controls

The verdict above grades the protocol layer. Every position also inherits the asset it holds and the chain it settles on. The least safe layer sets the position’s grade, and the position table names which one that is.

ChainVerdictGradeControl constraint
EthereumApproved sovereign No sequencer, no upgrade key, no operator who can be compelled — rule changes require social consensus.
The memo is public. The watching is the product: the terminal reads your clients’ wallets against this Register and flags the events above when they fire. $49 per advisor per month, first 14 days free. Start the trial.