LayerZero V2
This review finds LayerZero adverse as a dependency because of a realized infrastructure compromise. LayerZero is not a bridge itself; it is a messaging layer other protocols build bridges and omnichain tokens on, so its $6.7B tracked figure likely aggregates value already counted under downstream integrators like Stargate and USDT0 rather than value LayerZero itself custodies. This registry has not yet resolved that question of which entity holds the value. Security for each integration is configurable: an app picks which Decentralized Verifier Network (DVN) operators must attest to a message, from a single DVN up to a larger set. On 2026-04-18, attackers compromised LayerZero Labs’ own operational infrastructure, two internal nodes on separate clusters, to forge attestation data and steal about $292M (116,500 rsETH) from Kelp DAO’s OFT bridge, which used a 1-of-1 configuration trusting only LayerZero Labs’ own DVN. This was not a smart-contract bug. It proved that LayerZero Labs’ own infrastructure is a real, exploited single point of failure for any integration that does not add independent verification, which is the default posture for a large share of real deployments.
- A specific integration this registry would otherwise approve uses a multi-DVN configuration of at least 2-of-2 with operators sharing no common infrastructure, verified on-chain rather than from documentation
- LayerZero Labs publishes an independent post-incident security audit of its own DVN and RPC operational infrastructure, not only its smart contracts, with remediation confirmed
- Twelve consecutive months pass since 2026-04-18 with no second LayerZero Labs infrastructure-level compromise
- Message Library upgrade authority is fully disclosed and mapped to a named, accountable party
Watched nightly: a warning on its venues or files, or a cited document that changes, reopens the memo. The first confirmation is due 2026-11-17.
The research file
Mechanism
LayerZero is an omnichain messaging protocol. Its Omnichain Fungible Token (OFT) standard lets a token burn on a source chain and mint on a destination chain through LayerZero message passing, rather than locking into a shared liquidity pool. Stargate, LayerZero Labs’ own flagship bridge, was spun into a DAO and later reacquired for $110M. It is the largest OFT application and pools liquidity across chains. LayerZero’s Endpoint contracts pass messages; they do not themselves custody the pooled value that downstream applications hold. Counting LayerZero’s TVL alongside Stargate’s or USDT0’s therefore risks counting the same underlying value twice.
Control and the DVN trust model
Each application chooses X required plus Y-of-N optional DVNs that must attest to a message before delivery. About 35 DVN operators exist, including Google Cloud, Chainlink, Polyhedra Network, and LayerZero Labs itself, but the default and most common configuration for many integrators is a single DVN run by LayerZero Labs. In practice, most real deployments rely on LayerZero Labs’ own infrastructure, not a decentralized set. Endpoint contracts are stated to be immutable. Message Library contracts, which handle encoding and coordinate verification, are versioned and upgradeable, and this review could not confirm exactly who holds the power to upgrade them.
The April 2026 incident
Attackers, attributed with high confidence to Lazarus Group, breached two independent internal nodes LayerZero Labs operated on separate clusters, replaced their software to feed forged attestation data, and simultaneously DDoS’d a third-party RPC node to force reliance on the compromised internal ones. Kelp DAO’s rsETH OFT deployment used a 1-of-1 DVN configuration, LayerZero Labs’ DVN only, so the forged attestation was accepted without a cross-check, and about $292M was stolen. A second attempt near $95M was blocked when Kelp paused contracts after detection. LayerZero and Kelp have publicly disputed responsibility for the 1-of-1 configuration choice; Kelp is now migrating rsETH off the OFT standard entirely. LayerZero states the compromised nodes have been replaced and now recommends multi-DVN setups, but the incident itself is not in dispute.
Exit and dependency framing
There is no direct deposit or withdrawal product here to test for exit liquidity. LayerZero should be treated as a dependency under Ketju’s own object types for bridge, oracle, and curator risk that other positions depend on, not as a position a client can hold directly. Any approved Ketju position that moves through a LayerZero-secured OFT or Stargate pool inherits that specific integration’s DVN configuration as a control dependency. The Kelp incident shows this must be checked for each integration and each configuration. A multi-DVN integration and a 1-of-1 integration do not carry the same risk despite sharing the LayerZero name.
Comparison
Wormhole uses 19 Guardian validators and had its own major 2022 exploit, a smart-contract signature-verification bug rather than an infrastructure compromise, for $325M. Axelar uses a proof-of-stake validator set with delegated staking and slashing. Chainlink CCIP puts an independent Risk Management Network on top of its oracle network so a single compromised component cannot forge a message without a second, structurally separate system flagging it. That design does not depend on each integrator choosing extra verifiers as LayerZero’s configurable DVN model does. This review does not approve any of these alternatives; each would need its own memo. USDT0, a LayerZero OFT deployment, is reviewed separately in this registry.
Sources
The claims above trace to these. Where a number could not be independently verified, the thesis says so.
- LayerZero V2 overview · primary · accessed 2026-08-17
Supports: mechanism, X-of-Y-of-N model - Decentralized Verifier Networks overview · primary · accessed 2026-08-17
Supports: DVN architecture - LayerZero V2: Explaining DVNs · primary · accessed 2026-08-17
Supports: default DVN operators, operator count - Deployed endpoints, message libraries, and executors · primary · accessed 2026-08-17
Supports: immutable endpoints, upgradeable message libraries - Chainalysis — Inside the Kelp DAO bridge exploit · secondary · accessed 2026-08-17
Supports: incident forensics, RPC compromise mechanics, loss figure - The Block — Kelp DAO rsETH bridge exploited for roughly $292 million · secondary · accessed 2026-08-17
Supports: incident record, date - CoinDesk — LayerZero blames Kelp’s setup, attributes attack to Lazarus · secondary · accessed 2026-08-17
Supports: attribution, responsibility dispute - CoinDesk — Kelp says LayerZero approved the setup it blamed for the hack · secondary · accessed 2026-08-17
Supports: dispute over responsibility, CCT migration
Inherited controls
The research above describes the protocol layer. Every position also inherits the asset it holds and the chain it settles on. The layer with the most administrative power sets the position’s effective control; that describes control, not quality or suitability.
| Chain | Verdict | Control | Control constraint |
|---|---|---|---|
| Ethereum | Approved | No freeze key | No sequencer, no upgrade key, no operator who can be compelled. Rule changes require social consensus. |