Research summary
This review finds LayerZero adverse as a dependency because of a realized infrastructure compromise. LayerZero is not a bridge itself; it is a messaging layer other protocols build bridges and omnichain tokens on, so its $6.7B tracked figure likely aggregates value already counted under downstream integrators like Stargate and USDT0 rather than value LayerZero itself custodies. This registry has not yet resolved that question of which entity holds the value. Security for each integration is configurable: an app picks which Decentralized Verifier Network (DVN) operators must attest to a message, from a single DVN up to a larger set. On 2026-04-18, attackers compromised LayerZero Labs' own operational infrastructure, two internal nodes on separate clusters, to forge attestation data and steal about $292M (116,500 rsETH) from Kelp DAO's OFT bridge, which used a 1-of-1 configuration trusting only LayerZero Labs' own DVN. This was not a smart-contract bug. It proved that LayerZero Labs' own infrastructure is a real, exploited single point of failure for any integration that does not add independent verification, which is the default posture for a large share of real deployments.
Observable review triggers
- A specific integration this registry would otherwise approve uses a multi-DVN configuration of at least 2-of-2 with operators sharing no common infrastructure, verified on-chain rather than from documentation
- LayerZero Labs publishes an independent post-incident security audit of its own DVN and RPC operational infrastructure, not only its smart contracts, with remediation confirmed
- Twelve consecutive months pass since 2026-04-18 with no second LayerZero Labs infrastructure-level compromise
- Message Library upgrade authority is fully disclosed and mapped to a named, accountable party
Facts on file
- Verdict
- Rejected
- Type
- Other
- Chains examined
- Ethereum
- Reviewed
- Last confirmed