//LayerZero
C-

LayerZero

Risk Score 53/100·C+Value
Compare
$6.7BTVL·$714MFDV·BridgeWebsite →

LayerZero is the dominant cross-chain messaging protocol with strong institutional backing (Citadel Securities, DTCC, ICE) and the most widely adopted omnichain token standard. However, the April 2026 KelpDAO exploit ($292M) — in which LayerZero admitted its infrastructure and permissive DVN policy enabled the attack — marks a significant credibility event. Major clients including Kelp DAO and Solv Protocol ($700M+) migrated to alternative solutions, and bridge volume fell to historical lows. The fee switch has now failed quorum three times, large ZRO token unlocks continue through 2027, and ZRO trades near all-time lows. The Zero L1 institutional thesis remains intact but faces execution risk while the core protocol repairs its trust deficit.

Risk Breakdown

Top Risks

1

Infrastructure compromise confirmed: the April 2026 KelpDAO exploit ($292M) demonstrated that social engineering of LayerZero developers combined with DDoS-forced RPC failover can bypass DVN verification for single-verifier (1-of-1) applications. LayerZero admitted fault on May 9, 2026; $2B+ in TVL migrated to competing solutions.

2

DVN permissive configuration policy unmitigated: LayerZero permits 1-of-1 DVN setups with no enforced minimum threshold. The KelpDAO exploit confirmed this is a structural vulnerability, not merely application misconfiguration — the protocol design enables it.

3

Only ~25% of 1B ZRO supply circulating; a large Strategic Partners cliff unlock is scheduled for October 2026; fee switch failed quorum for the third time in May 2026, leaving ZRO with no active revenue accrual mechanism through at least November 2026.

Frequently Asked Questions

Is LayerZero safe to use?
LayerZero receives a C- risk grade (53/100) from Hindenrank, where lower scores indicate lower risk. LayerZero is the dominant cross-chain messaging protocol with strong institutional backing (Citadel Securities, DTCC, ICE) and the most widely adopted omnichain token standard. However, the April 2026 KelpDAO exploit ($292M) — in which LayerZero admitted its infrastructure and permissive DVN policy enabled the attack — marks a significant credibility event. Major clients including Kelp DAO and Solv Protocol ($700M+) migrated to alternative solutions, and bridge volume fell to historical lows. The fee switch has now failed quorum three times, large ZRO token unlocks continue through 2027, and ZRO trades near all-time lows. The Zero L1 institutional thesis remains intact but faces execution risk while the core protocol repairs its trust deficit. LayerZero is the leading cross-chain messaging protocol, enabling communication across 70+ blockchains. It powers the OFT (Omnichain Fungible Token) standard and acquired Stargate bridge ($345M TVL) in August 2025. In February 2026, LayerZero announced the Zero blockchain with strategic backing from Citadel Securities, DTCC, ICE, and ARK Invest. However, the April 2026 KelpDAO exploit ($292M, attributed to Lazarus Group) severely damaged trust: LayerZero admitted fault on May 9, 2026, and $2B+ in client TVL migrated to competing solutions. The fee switch failed quorum for the third time in May 2026, and a major token unlock for Strategic Partners is scheduled for October 2026.
What are the main risks of using LayerZero?
The key risks identified for LayerZero are: (1) LayerZero's own infrastructure was compromised in the April 2026 KelpDAO hack ($292M via Lazarus Group). LayerZero admitted they made a mistake by allowing risky single-verifier configurations. $2B+ in client TVL has since migrated to competitors. (2) Only ~25% of ZRO tokens are circulating, with a major Strategic Partners cliff unlock scheduled for October 2026 and continued dilution through 2027 (3) The fee switch failed quorum for the third time in May 2026 — ZRO still has no active revenue accrual mechanism through at least November 2026 (4) Bridge volume dropped to a historical low of $91M following the KelpDAO exploit — LayerZero's network effects are being actively eroded by client departures (5) LayerZero's pivot to building Zero L1 for institutions creates execution risk while the core protocol still has unresolved DVN configuration safety gaps
What is LayerZero's risk score breakdown?
LayerZero scores 53/100 across eight risk dimensions: Mechanism Novelty: 6/15, Interaction Severity: 13/20, Oracle Surface: 3/10, Documentation Gaps: 4/10, Track Record: 12/15, Scale Exposure: 9/10, Regulatory Risk: 2/10, Vitality Risk: 4/10. The highest risk area is Scale Exposure at 9/10.
How does LayerZero compare to other Bridge protocols?
Among 28 rated Bridge protocols on Hindenrank, LayerZero ranks #23 by safety (lowest risk score = safest). Its 53/100 risk score and C- grade place it among the riskier Bridge protocols.
Has LayerZero ever been hacked or exploited?
LayerZero scores 12/15 on the Track Record risk dimension, indicating some history of security incidents or exploits. Higher scores reflect more severe or frequent incidents. Review the full risk report for details.
Last scanned 2026-06-04

Get risk alerts before it's too late

Weekly grade changes, downgrade alerts, and new protocol risk findings. Free.