LayerZero is the dominant cross-chain messaging protocol with strong institutional backing (Citadel Securities, DTCC, ICE) and the most widely adopted omnichain token standard. However, the April 2026 KelpDAO exploit ($292M) — in which LayerZero admitted its infrastructure and permissive DVN policy enabled the attack — marks a significant credibility event. Major clients including Kelp DAO and Solv Protocol ($700M+) migrated to alternative solutions, and bridge volume fell to historical lows. The fee switch has now failed quorum three times, large ZRO token unlocks continue through 2027, and ZRO trades near all-time lows. The Zero L1 institutional thesis remains intact but faces execution risk while the core protocol repairs its trust deficit.
Risk Breakdown
Top Risks
Infrastructure compromise confirmed: the April 2026 KelpDAO exploit ($292M) demonstrated that social engineering of LayerZero developers combined with DDoS-forced RPC failover can bypass DVN verification for single-verifier (1-of-1) applications. LayerZero admitted fault on May 9, 2026; $2B+ in TVL migrated to competing solutions.
DVN permissive configuration policy unmitigated: LayerZero permits 1-of-1 DVN setups with no enforced minimum threshold. The KelpDAO exploit confirmed this is a structural vulnerability, not merely application misconfiguration — the protocol design enables it.
Only ~25% of 1B ZRO supply circulating; a large Strategic Partners cliff unlock is scheduled for October 2026; fee switch failed quorum for the third time in May 2026, leaving ZRO with no active revenue accrual mechanism through at least November 2026.
Frequently Asked Questions
Is LayerZero safe to use?
What are the main risks of using LayerZero?
What is LayerZero's risk score breakdown?
How does LayerZero compare to other Bridge protocols?
Has LayerZero ever been hacked or exploited?
Get risk alerts before it's too late
Weekly grade changes, downgrade alerts, and new protocol risk findings. Free.