How Does LayerZero Work?

Bridge|Risk C-|8 mechanisms|7 interactions

LayerZero is the leading cross-chain messaging protocol, enabling communication across 70+ blockchains. It powers the OFT (Omnichain Fungible Token) standard and acquired Stargate bridge ($345M TVL) in August 2025. In February 2026, LayerZero announced the Zero blockchain with strategic backing from Citadel Securities, DTCC, ICE, and ARK Invest. However, the April 2026 KelpDAO exploit ($292M, attributed to Lazarus Group) severely damaged trust: LayerZero admitted fault on May 9, 2026, and $2B+ in client TVL migrated to competing solutions. The fee switch failed quorum for the third time in May 2026, and a major token unlock for Strategic Partners is scheduled for October 2026.

TVL

$6.7B

Sector

Bridge

Risk Grade

C-

Value Grade

C+

Core Mechanisms

8.1.3

Novel

Ultra-light message passing with modular DVN verification: applications configure X-of-Y-of-N security stacks from permissionless DVN marketplace

LayerZero V2 separates message verification from execution. DVNs independently verify payloadHash of cross-chain messages. Applications choose their own security threshold (e.g., 2-of-3 DVNs from Google Cloud, Polyhedra, Axelar). This modular approach is novel — no other bridge delegates security configuration entirely to the application layer.

8.2.3

Novel

OFT (Omnichain Fungible Token) standard enabling native cross-chain token transfers via burn-and-mint through LayerZero messaging

OFT tokens are natively transferable across 70+ chains without wrapped representations. Tokens are burned on source chain and minted on destination, maintaining a global supply invariant verified by DVNs. The September 2025 $GAIN exploit showed peer initialization is a critical security boundary.

8.1.2

Stargate liquidity pool bridge enabling instant cross-chain swaps with unified liquidity across chains

Acquired August 2025 for $110M. Stargate uses Delta algorithm for cross-chain liquidity rebalancing with $345M TVL. Liquidity pools on each chain enable instant finality for cross-chain transfers. Revenue (~$2M/yr) feeds into ZRO buyback.

8.4.1

Permissionless executor network delivers verified messages to destination chains for per-message fees

Executors are separate from DVNs — they deliver messages after verification. Any entity can run an executor. Fee is paid by the application or user. Liveness depends on executor profitability.

8.4.2

Novel

DVN operators incentivized via verification fees; any entity can build and operate a DVN with custom verification schemes

DVN marketplace is permissionless — Google Cloud, Polyhedra, Axelar, and others operate DVNs. DVN Adapters allow integration of third-party verification systems (native bridges, middlechains). Economic security depends on each application's DVN selection, not protocol-level guarantees.

5.1.1

ZRO token-weighted governance with immutable on-chain fee switch referendum every 6 months; 40.59% quorum required

Semi-annual on-chain vote to activate/deactivate protocol fee switch. If activated, LayerZero charges a fee equal to aggregate DVN + executor cost, converting 100% to ZRO buyback-and-burn. Four referendums held to date; third failed quorum in May 2026. Quorum is 230M ZRO with >50% approval threshold.

1.2.1

3-year linear vesting for strategic partners (32.2%) and core contributors (25.5%) with bi-weekly unlocks

1B total ZRO supply. 38.3% community allocation (includes airdrop). ~252M ZRO circulating (25.2%) after the March 20, 2026 unlock of 25.7M ZRO. Major Strategic Partners cliff scheduled October 2, 2026. Continued unlock pressure through 2027.

1.2.3

Retroactive ZRO airdrop (June 2024) to early LayerZero users based on historical cross-chain activity

ZRO launched via airdrop in June 2024. Extensive Sybil filtering applied but controversy over criteria. Recipients had option to donate to Protocol Guild. Significant initial sell pressure drove price from $4.79 to sub-$3 within weeks.

How the Pieces Interact

DVN verification networkCross-chain message passing (OFT/OApp)Critical

A compromised or colluding set of DVNs can forge payloadHash verification, allowing minting of unbacked OFT tokens or execution of malicious cross-chain messages. Applications with weak security stacks (e.g., single DVN) are especially vulnerable. The September 2025 $GAIN exploit demonstrated this at the peer initialization level. The April 2026 KelpDAO exploit ($292M) confirmed this attack path at infrastructure scale: social engineering of a LayerZero Labs developer + DDoS-forced RPC failover bypassed DVN verification for Kelp's single-verifier configuration.

OFT global supply invariantMulti-chain deployment (70+ chains)Critical

OFT tokens maintain a burn-and-mint invariant across 70+ chains. If any single chain's OFT contract is compromised (unauthorized peer, contract upgrade), tokens can be minted without corresponding burns, breaking the global supply invariant. The attack surface scales linearly with chain count.

ZRO vesting unlocks (75% locked)Thin ZRO liquidityHigh

With ~25% circulating after the March 2026 unlock, bi-weekly unlocks continue to inject significant new supply into thin markets. A major Strategic Partners cliff is scheduled for October 2, 2026. Coordinated insider selling at unlock points could crash ZRO price, undermining the economic value of the fee switch buyback mechanism.

Application-configured security stacksPermissionless DVN marketplaceHigh

Applications choose their own DVN configurations. Inexperienced developers may select weak security stacks (single DVN, low-reputation verifiers) to save on fees. Users interacting with these applications bear the security risk without visibility into the underlying DVN configuration. The KelpDAO exploit confirmed this risk is not theoretical — LayerZero's permissive policy (no enforced minimum DVN threshold) enabled the incident.

OFT peer initializationPermissionless chain deploymentHigh

The $GAIN exploit showed that unauthorized peer initialization on a new chain can create a backdoor to mint tokens. As OFT deployments proliferate across 70+ chains, the attack surface for peer initialization exploits grows. Each new chain deployment is a potential entry point.

What Could Go Wrong

  1. Infrastructure compromise confirmed: the April 2026 KelpDAO exploit ($292M) demonstrated that social engineering of LayerZero developers combined with DDoS-forced RPC failover can bypass DVN verification for single-verifier (1-of-1) applications. LayerZero admitted fault on May 9, 2026; $2B+ in TVL migrated to competing solutions.
  2. DVN permissive configuration policy unmitigated: LayerZero permits 1-of-1 DVN setups with no enforced minimum threshold. The KelpDAO exploit confirmed this is a structural vulnerability, not merely application misconfiguration — the protocol design enables it.
  3. Only ~25% of 1B ZRO supply circulating; a large Strategic Partners cliff unlock is scheduled for October 2026; fee switch failed quorum for the third time in May 2026, leaving ZRO with no active revenue accrual mechanism through at least November 2026.

DVN Collusion Enables Mass OFT Counterfeiting

Tail

Trigger: An attacker compromises or colludes with a sufficient number of DVNs in a widely-used security stack, enabling forged cross-chain message verification across multiple OFT deployments simultaneously

  1. 1.Attacker identifies OFT deployments using a weak DVN security stack (e.g., 1-of-1 or 2-of-2 with correlated DVNs) and compromises the required DVN threshold Attacker can forge payloadHash verification for any message routed through the compromised security stack
  2. 2.Forged verification enables minting of unbacked OFT tokens across multiple destination chains without corresponding burns on source chains Global supply invariant for affected OFT tokens is broken; counterfeit tokens enter circulation on destination chains
  3. 3.Attacker sells counterfeit OFT tokens on DEXs across multiple chains before the exploit is detected LP providers suffer losses as counterfeit tokens drain pool liquidity; affected token prices crash as supply inflation is discovered
  4. 4.Trust in all LayerZero-verified OFT tokens is shattered; protocols delist OFT tokens and users flee cross-chain positions Cross-chain liquidity evaporates; protocols depending on OFT tokens for cross-chain operations face insolvency; ZRO price crashes as confidence in the messaging layer collapses

Risk Profile at a Glance

Mechanism Novelty6/15
Interaction Severity13/20
Oracle Surface3/10
Documentation Gaps4/10
Track Record12/15
Scale Exposure9/10
Regulatory Risk2/10
Vitality Risk4/10
C-

Overall: C- (53/100)

Lower score = safer

More on LayerZero

Related Bridge Explainers