The memo
REJECTED AS A DEPENDENCY, ON A REALIZED INFRASTRUCTURE COMPROMISE. LayerZero is not a bridge itself; it is a messaging layer other protocols build bridges and omnichain tokens on, so its $6.7B tracked figure likely aggregates value already counted under downstream integrators like Stargate and USDT0 rather than value LayerZero itself custodies — an entity-resolution question this registry has not yet resolved. Security per integration is configurable: an app picks which Decentralized Verifier Network (DVN) operators must attest to a message, from a single DVN up to a larger set. On 2026-04-18, attackers compromised LayerZero Labs' own operational infrastructure — two internal nodes on separate clusters — to forge attestation data and steal about $292M (116,500 rsETH) from Kelp DAO's OFT bridge, which used a 1-of-1 configuration trusting only LayerZero Labs' own DVN. This was not a smart-contract bug; it was proof that LayerZero Labs' own infrastructure is a real, exploited single point of failure for any integration that does not add independent verification, which is the default posture for a large share of real deployments.
What would reopen the file
- A specific integration this registry would otherwise approve uses a multi-DVN configuration of at least 2-of-2 with operators sharing no common infrastructure, verified on-chain rather than from documentation
- LayerZero Labs publishes an independent post-incident security audit of its own DVN and RPC operational infrastructure, not only its smart contracts, with remediation confirmed
- Twelve consecutive months pass since 2026-04-18 with no second LayerZero Labs infrastructure-level compromise
- Message Library upgrade authority is fully disclosed and mapped to a named, accountable party
Facts on file
- Verdict
- Rejected
- Exposure
- other
- Chains examined
- Ethereum
- Memo version
- v1
- Reviewed
- Next review