Skip to main content
AVOID.NET

Audit log

Every state-changing event for LayerZero Executor Wallet Incident (July 2026): moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.

  1. #1publishby system:backfill
    2026-09-15 12:07:11Z
    Score: ?? (no score change)
    anchoranchored
    chain
    mainnet-betaslot 447,246,011
    sig
    4PX4RhvYhCpq…t14sNegrexplorer ↗
    hash
    8bWetzLekgFE…RdUBRrqqsha256 → base58
    verifying row…full verify ↗
    canonical bytes (14058 B) ▸
    {"actor":"system:backfill","investigation_id":"533753f4-3c8d-44ec-8e5c-42f5b205906e","kind":"publish","page_slug":"layerzero-executor-wallet-incident-july-2026","published_at":"2026-09-15T12:07:11.676Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"LayerZero Executor Wallet Incident (July 2026)","sections":[{"content":"On July 15, 2026, blockchain security firm PeckShield posted an alert on X (formerly Twitter) flagging what it characterized as a potential compromise of LayerZero executor wallets. On-chain analyst Specter separately reported signs of unusual outflows, citing approximately $2.1–2.4 million in assets moved out of wallets associated with the LayerZero protocol across multiple blockchain networks. The reported figure of $2.4 million circulated widely in crypto media within hours of the initial alert. LayerZero Core responded on July 15, 2026, stating: 'The transfer was not an attack, but a normal operational fund rebalancing. No hack occurred. No user funds were at risk. Protocol operations remain unaffected.' The company described the movements as routine internal inventory rebalancing of operational funds rather than evidence of a security breach. No independent on-chain forensic report or post-mortem has been published that contradicts LayerZero's account as of September 2026.","heading":"Incident Overview","severity":"medium","sources":[{"credibility":2,"name":"LayerZero Denies Hack Claim, Says User Funds Are Safe — Bloomingbit","type":"news_article","url":"https://en.bloomingbit.io/feed/news/116300"},{"credibility":2,"name":"LayerZero Executor Wallet Hack Claim Over $2.4M Across 8 Blockchains Called False Alarm — Live Bitcoin News","type":"news_article","url":"https://www.livebitcoinnews.com/layerzero-executor-wallet-hack-claim-over-2-4m-across-8-blockchains-called-false-alarm/"},{"credibility":2,"name":"LayerZero Team Suspects $2.1 Million Hack — Bloomingbit","type":"news_article","url":"https://en.bloomingbit.io/feed/news/116297"}]},{"content":"According to PeckShield and secondary crypto news reporting, the flagged transactions showed outflows from LayerZero executor wallets across eight blockchain networks: Ethereum, BNB Chain, Base, Arbitrum, Avalanche, Optimism, Mantle, and Plasma. Reports stated the assets were bridged to Ethereum via Stargate and Relay, with the consolidated holdings reportedly amounting to approximately 956 ETH (valued at roughly $1.79 million at the time) and approximately $322,000 in USDC. These figures were cited in multiple outlets but originate from the same initial PeckShield alert and Specter report, rather than from independent parallel analyses. LayerZero has not disputed that the transfers occurred, only their characterization as a hack.","heading":"Reported Fund Movements","severity":"low","sources":[{"credibility":2,"name":"LayerZero Executor Wallets Undergo Security Breach, $2.4 Million Drained — Blockchain Reporter","type":"news_article","url":"https://blockchainreporter.net/layerzero-executor-wallets-undergo-security-breach-2-4-million-drained"},{"credibility":3,"name":"Suspected $2.4 Million Exploit Targets LayerZero Executor Wallets — HokaNews","type":"news_article","url":"https://www.hokanews.com/2026/07/suspected-24-million-exploit-targets.html"},{"credibility":2,"name":"LayerZero Wallet Hack Causes $2.4M Multi-Chain Theft — Cryptonomist","type":"news_article","url":"https://en.cryptonomist.ch/2026/07/15/layerzero-wallet-hack/"}]},{"content":"LayerZero Core issued a denial on July 15, 2026, the same day the initial alert was posted. The company stated that the transfers in question were routine internal inventory rebalancing of operational protocol funds, that no exploit occurred, and that no user funds were at risk at any point. LayerZero's official blog published a support update on July 24, 2026, which is consistent with a follow-up operational communication following the incident. The company has not published a detailed technical post-mortem addressing the specific wallet movements flagged by PeckShield and Specter. The absence of a detailed public technical accounting means that LayerZero's denial, while plausible for a protocol that regularly moves operational liquidity across chains, cannot be fully corroborated or independently refuted from open-source information alone.","heading":"LayerZero's Official Position","severity":"low","sources":[{"credibility":1,"name":"Support Update — July 24, 2026 | LayerZero (official blog)","type":"official","url":"https://layerzero.network/blog/support-update-july-24-2026"},{"credibility":2,"name":"LayerZero Denies Hack Claim, Says User Funds Are Safe — Bloomingbit","type":"news_article","url":"https://en.bloomingbit.io/feed/news/116300"}]},{"content":"The July 2026 incident must be read in the context of the April 18, 2026 Kelp DAO bridge exploit, in which approximately $292 million in rsETH assets were stolen from a LayerZero-connected bridge. In its post-mortem, LayerZero attributed that incident to North Korea's Lazarus Group (specifically the TraderTraitor cluster), identifying a single-DVN (Decentralized Verifier Network) configuration error in Kelp DAO's implementation as the enabling vulnerability. LayerZero acknowledged in a May 2026 statement that it 'made a mistake' regarding aspects of that incident, though the precise scope of that admission was disputed by Kelp DAO, which claimed LayerZero had approved the configuration it later criticized. The prior high-profile failure of LayerZero-adjacent infrastructure raised the baseline level of scrutiny applied to any anomalous movement of LayerZero operational wallets, which contributed to the rapid amplification of the July 2026 alert.","heading":"Contextual Risk: Prior Kelp DAO Incident","severity":"high","sources":[{"credibility":1,"name":"LayerZero says it 'made a mistake' in $292 Million Kelp exploit — CoinDesk","type":"news_article","url":"https://www.coindesk.com/tech/2026/05/09/layerzero-says-it-made-a-mistake-in-usd292-million-kelp-exploit"},{"credibility":1,"name":"KelpDAO Incident Statement | LayerZero (official blog)","type":"official","url":"https://layerzero.network/blog/kelpdao-incident-statement"},{"credibility":1,"name":"Kelp says LayerZero approved setup it blamed for $292 million bridge hack — CoinDesk","type":"news_article","url":"https://www.coindesk.com/web3/2026/05/05/kelp-claims-that-layerzero-approved-the-setup-it-blamed-for-usd292-million-bridge-hack"},{"credibility":1,"name":"Inside the KelpDAO Bridge Exploit — Chainalysis","type":"research","url":"https://www.chainalysis.com/blog/kelpdao-bridge-exploit-april-2026/"},{"credibility":2,"name":"LayerZero Post Mortem Shows Lazarus Group Stole $290M From KelpDAO via RPC Node Compromise — The Defiant","type":"news_article","url":"https://thedefiant.io/news/hacks/lazarus-kelpdao-290m-layerzero-rpc-hack-da50p3"}]},{"content":"The initial alert originated from PeckShield, a recognized blockchain security monitoring firm (Tier 2), and was corroborated by on-chain analyst Specter. Both are credible early-warning sources but their alerts are not equivalent to a confirmed post-mortem finding. The resulting coverage was amplified predominantly by Tier 2 and Tier 3 crypto news outlets, none of which conducted independent on-chain verification beyond summarizing the PeckShield and Specter reports. LayerZero's denial was issued the same day and has not been retracted or updated. No Tier 1 outlet (Reuters, Bloomberg, WSJ) reported on this incident as a confirmed exploit. No regulatory body filed action. No court filing exists. The claim that this constitutes a confirmed exploit is therefore low-confidence. The claim that LayerZero moved funds in an unusual manner that warranted an alert is medium-confidence. The claim that the movement represented a hack or a security breach is unverified and disputed by the entity most capable of providing context.","heading":"Source Quality and Confidence Assessment","severity":"low","sources":[{"credibility":2,"name":"Crypto Fraud Watch: The Hack That Wasn't — Coin Counsel","type":"news_article","url":"https://www.coin-counsel.com/blog/crypto-fraud-watch-an-18m-oracle-heist-the-hack-that-wasnt-and-wall-streets-stablecoin-warning"}]}],"sources_used":[{"credibility":2,"name":"LayerZero Denies Hack Claim, Says User Funds Are Safe — Bloomingbit","type":"news_article","url":"https://en.bloomingbit.io/feed/news/116300"},{"credibility":2,"name":"LayerZero Team Suspects $2.1 Million Hack — Bloomingbit","type":"news_article","url":"https://en.bloomingbit.io/feed/news/116297"},{"credibility":2,"name":"LayerZero Executor Wallet Hack Claim Over $2.4M Across 8 Blockchains Called False Alarm — Live Bitcoin News","type":"news_article","url":"https://www.livebitcoinnews.com/layerzero-executor-wallet-hack-claim-over-2-4m-across-8-blockchains-called-false-alarm/"},{"credibility":2,"name":"LayerZero Executor Wallets Undergo Security Breach, $2.4 Million Drained — Blockchain Reporter","type":"news_article","url":"https://blockchainreporter.net/layerzero-executor-wallets-undergo-security-breach-2-4-million-drained"},{"credibility":2,"name":"LayerZero Wallet Hack Causes $2.4M Multi-Chain Theft — Cryptonomist","type":"news_article","url":"https://en.cryptonomist.ch/2026/07/15/layerzero-wallet-hack/"},{"credibility":3,"name":"Suspected $2.4 Million Exploit Targets LayerZero Executor Wallets — HokaNews","type":"news_article","url":"https://www.hokanews.com/2026/07/suspected-24-million-exploit-targets.html"},{"credibility":1,"name":"Support Update — July 24, 2026 | LayerZero (official blog)","type":"official","url":"https://layerzero.network/blog/support-update-july-24-2026"},{"credibility":1,"name":"KelpDAO Incident Statement | LayerZero (official blog)","type":"official","url":"https://layerzero.network/blog/kelpdao-incident-statement"},{"credibility":1,"name":"LayerZero says it 'made a mistake' in $292 Million Kelp exploit — CoinDesk","type":"news_article","url":"https://www.coindesk.com/tech/2026/05/09/layerzero-says-it-made-a-mistake-in-usd292-million-kelp-exploit"},{"credibility":1,"name":"Kelp says LayerZero approved setup it blamed for $292 million bridge hack — CoinDesk","type":"news_article","url":"https://www.coindesk.com/web3/2026/05/05/kelp-claims-that-layerzero-approved-the-setup-it-blamed-for-usd292-million-bridge-hack"},{"credibility":1,"name":"Inside the KelpDAO Bridge Exploit — Chainalysis","type":"research","url":"https://www.chainalysis.com/blog/kelpdao-bridge-exploit-april-2026/"},{"credibility":2,"name":"LayerZero Post Mortem Shows Lazarus Group Stole $290M From KelpDAO via RPC Node Compromise — The Defiant","type":"news_article","url":"https://thedefiant.io/news/hacks/lazarus-kelpdao-290m-layerzero-rpc-hack-da50p3"},{"credibility":2,"name":"Crypto Fraud Watch: The Hack That Wasn't — Coin Counsel","type":"news_article","url":"https://www.coin-counsel.com/blog/crypto-fraud-watch-an-18m-oracle-heist-the-hack-that-wasnt-and-wall-streets-stablecoin-warning"}],"summary":"On July 15, 2026, security firm PeckShield and on-chain analyst Specter reported that LayerZero executor wallets appeared to have been drained of approximately $2.4 million across eight blockchain networks. LayerZero Core responded the same day, stating the transfers were routine internal inventory rebalancing and that no exploit had occurred and no user funds were at risk. The incident was not independently confirmed as a security breach, and as of the date of this investigation LayerZero's denial has not been publicly contradicted by on-chain forensic analysis or a third-party post-mortem.","timeline":[{"date":"2026-04-18","event":"Kelp DAO bridge exploit drains approximately $292 million from a LayerZero-connected bridge. LayerZero later attributes the attack to North Korea's Lazarus Group (TraderTraitor cluster) and a single-DVN configuration failure in Kelp DAO's setup.","source":"CoinDesk / Chainalysis","source_url":"https://www.coindesk.com/tech/2026/04/20/layerzero-blames-kelp-s-setup-for-usd290-million-exploit-attributes-it-to-north-korea-s-lazarus"},{"date":"2026-05-05","event":"Kelp DAO publicly disputes LayerZero's post-mortem, claiming LayerZero had approved the single-DVN configuration it later criticized.","source":"CoinDesk","source_url":"https://www.coindesk.com/web3/2026/05/05/kelp-claims-that-layerzero-approved-the-setup-it-blamed-for-usd292-million-bridge-hack"},{"date":"2026-05-09","event":"LayerZero acknowledges it 'made a mistake' in connection with the Kelp DAO exploit.","source":"CoinDesk","source_url":"https://www.coindesk.com/tech/2026/05/09/layerzero-says-it-made-a-mistake-in-usd292-million-kelp-exploit"},{"date":"2026-07-15","event":"PeckShield and on-chain analyst Specter post alerts on X flagging anomalous outflows from LayerZero executor wallets across eight blockchain networks, reporting approximately $2.1–2.4 million in assets moved and bridged to Ethereum.","source":"Bloomingbit / Blockchain Reporter","source_url":"https://en.bloomingbit.io/feed/news/116297"},{"date":"2026-07-15","event":"LayerZero Core issues a same-day denial, stating the transfers were routine internal inventory rebalancing and that no hack occurred and no user funds were at risk.","source":"Bloomingbit","source_url":"https://en.bloomingbit.io/feed/news/116300"},{"date":"2026-07-15","event":"Multiple crypto media outlets including Cryptonomist, Blockchain Reporter, and Coinpedia publish articles characterizing the incident as a confirmed or suspected hack; Live Bitcoin News subsequently publishes the LayerZero denial and characterizes the alarm as a false alarm.","source":"Live Bitcoin News","source_url":"https://www.livebitcoinnews.com/layerzero-executor-wallet-hack-claim-over-2-4m-across-8-blockchains-called-false-alarm/"},{"date":"2026-07-24","event":"LayerZero publishes a support update blog post following the incident.","source":"LayerZero official blog","source_url":"https://layerzero.network/blog/support-update-july-24-2026"}]},"v":1}
    Verify offline (run on your own machine)
    python -m src.verify_decision 01c11035-aef7-4fdf-839f-99d9f947e012
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine — python -m src.verify_decision <event_id>.