LayerZero V2
Rejected venues wait the longest for re-review; a rejection has to earn another look before the scheduled date.
REJECTED AS A DEPENDENCY, ON A REALIZED INFRASTRUCTURE COMPROMISE. LayerZero is not a bridge itself; it is a messaging layer other protocols build bridges and omnichain tokens on, so its $6.7B tracked figure likely aggregates value already counted under downstream integrators like Stargate and USDT0 rather than value LayerZero itself custodies — an entity-resolution question this registry has not yet resolved. Security per integration is configurable: an app picks which Decentralized Verifier Network (DVN) operators must attest to a message, from a single DVN up to a larger set. On 2026-04-18, attackers compromised LayerZero Labs’ own operational infrastructure — two internal nodes on separate clusters — to forge attestation data and steal about $292M (116,500 rsETH) from Kelp DAO’s OFT bridge, which used a 1-of-1 configuration trusting only LayerZero Labs’ own DVN. This was not a smart-contract bug; it was proof that LayerZero Labs’ own infrastructure is a real, exploited single point of failure for any integration that does not add independent verification, which is the default posture for a large share of real deployments.
- A specific integration this registry would otherwise approve uses a multi-DVN configuration of at least 2-of-2 with operators sharing no common infrastructure, verified on-chain rather than from documentation
- LayerZero Labs publishes an independent post-incident security audit of its own DVN and RPC operational infrastructure, not only its smart contracts, with remediation confirmed
- Twelve consecutive months pass since 2026-04-18 with no second LayerZero Labs infrastructure-level compromise
- Message Library upgrade authority is fully disclosed and mapped to a named, accountable party
The research file
Mechanism
LayerZero is an omnichain messaging protocol. Its Omnichain Fungible Token (OFT) standard lets a token burn on a source chain and mint on a destination chain via LayerZero message passing, rather than locking into a shared liquidity pool. Stargate, LayerZero Labs’ own flagship bridge (spun into a DAO, later reacquired for $110M), is the largest OFT application and pools liquidity across chains. LayerZero’s Endpoint contracts pass messages; they do not themselves custody the pooled value that downstream applications hold, which is why counting LayerZero’s TVL alongside Stargate’s or USDT0’s risks double-counting the same underlying value.
Control and the DVN trust model
Each application chooses X required plus Y-of-N optional DVNs that must attest to a message before delivery. About 35 DVN operators exist, including Google Cloud, Chainlink, Polyhedra Network, and LayerZero Labs itself, but the default and most common configuration for many integrators is a single DVN run by LayerZero Labs — meaning the practical trust assumption for most real deployments reduces to trusting LayerZero Labs’ own infrastructure, not a decentralized set. Endpoint contracts are stated to be immutable; Message Library contracts, which handle encoding and verification orchestration, are versioned and upgradeable, and this review could not confirm exactly who holds upgrade authority over them.
The April 2026 incident
Attackers, attributed with high confidence to Lazarus Group, breached two independent internal nodes LayerZero Labs operated on separate clusters, replaced their software to feed forged attestation data, and simultaneously DDoS’d a third-party RPC node to force reliance on the compromised internal ones. Kelp DAO’s rsETH OFT deployment used a 1-of-1 DVN configuration — LayerZero Labs’ DVN only — so the forged attestation was accepted without cross-check, and about $292M was stolen; a second attempt near $95M was blocked when Kelp paused contracts post-detection. LayerZero and Kelp have publicly disputed responsibility for the 1-of-1 configuration choice; Kelp is now migrating rsETH off the OFT standard entirely. LayerZero states the compromised nodes have been replaced and now recommends multi-DVN setups, but the incident itself is not in dispute.
Exit and dependency framing
There is no direct deposit or withdrawal product here to test for exit liquidity — LayerZero should be modeled as a dependency, in the sense of Ketju’s own object taxonomy for bridge, oracle, and curator risk that other positions depend on, not as a directly allocable position. Any approved Ketju position that moves through a LayerZero-secured OFT or Stargate pool inherits that specific integration’s DVN configuration as a control dependency, and the Kelp incident shows this must be checked per integration, per configuration — a multi-DVN integration and a 1-of-1 integration do not carry the same risk despite sharing the LayerZero name.
Comparison
Wormhole uses 19 Guardian validators and had its own major 2022 exploit (a smart-contract signature-verification bug, not an infrastructure compromise, $325M). Axelar uses a proof-of-stake validator set with delegated staking and slashing. Chainlink CCIP layers an independent Risk Management Network on top of its oracle network specifically so a single compromised component cannot forge a message without a second, structurally separate system flagging it — a design that does not depend on each integrator opting into extra verifiers the way LayerZero’s configurable DVN model does. None of these alternatives are approved by this review; each would need its own memo, and USDT0 — a LayerZero OFT deployment — is reviewed separately in this registry.
Sources
The claims above trace to these. Where a number could not be independently verified, the thesis says so.
- LayerZero V2 overview · primary · accessed 2026-08-17
Supports: mechanism, X-of-Y-of-N model - Decentralized Verifier Networks overview · primary · accessed 2026-08-17
Supports: DVN architecture - LayerZero V2: Explaining DVNs · primary · accessed 2026-08-17
Supports: default DVN operators, operator count - Deployed endpoints, message libraries, and executors · primary · accessed 2026-08-17
Supports: immutable endpoints, upgradeable message libraries - Chainalysis — Inside the Kelp DAO bridge exploit · secondary · accessed 2026-08-17
Supports: incident forensics, RPC compromise mechanics, loss figure - The Block — Kelp DAO rsETH bridge exploited for roughly $292 million · secondary · accessed 2026-08-17
Supports: incident record, date - CoinDesk — LayerZero blames Kelp’s setup, attributes attack to Lazarus · secondary · accessed 2026-08-17
Supports: attribution, responsibility dispute - CoinDesk — Kelp says LayerZero approved the setup it blamed for the hack · secondary · accessed 2026-08-17
Supports: dispute over responsibility, CCT migration
Inherited controls
The verdict above grades the protocol layer. Every position also inherits the asset it holds and the chain it settles on. The least safe layer sets the position’s grade, and the position table names which one that is.
| Chain | Verdict | Grade | Control constraint |
|---|---|---|---|
| Ethereum | Approved | sovereign | No sequencer, no upgrade key, no operator who can be compelled — rule changes require social consensus. |