Skip to main content
AVOID.NET
LayerZeroreviewed 2026-09-06 · 41 claims checked

Fact-check findings

What an automated fact-checker found when it re-read LayerZero against the sources the page cites. Only the most recent review is shown.

Read this first

These findings are produced by an automated reviewer, and its results vary between runs: the same page, checked three times on the same day, came back with 15%, 20% and 34% of its claims disputed, mostly because each run extracted a different number of claims. Treat what follows as leads, not rulings.

“Disputed” means the reviewer could not reconcile the claim with the evidence it cited. It does not mean the claim is false. “Unverifiable” means no reachable source settled it either way.

Nothing here changes the page on its own. A proposed correction is applied only after a human moderator approves it; until then the page reads as it did when reviewed.

disputed

2 claims

The reviewer could not reconcile the claim with the evidence it cited. This is a lead, not a ruling that the claim is false.

  1. #13[disputed][awaiting moderator]in section: Attack Vector: Social Engineering and RPC Node Compromise
    Attribution was made with preliminary confidence by LayerZero and confirmed independently by Mandiant, CrowdStrike, and Chainalysis.
    reviewerThe attack has been attributed to TraderTraitor (UNC4899), a Lazarus Group subunit, with preliminary confidence by LayerZero and confirmed independently by Mandiant, CrowdStrike, and Chainalysis.The page's own cited Chainalysis source does not independently confirm attribution — it explicitly cites LayerZero's attribution claim rather than presenting its own conclusion. Mandiant and CrowdStrike's independent attribution is corroborated elsewhere, but including Chainalysis as a third independent confirmer overstates what the cited source says.
    Proposed correction (not yet applied)
    Attribution was made with preliminary confidence by LayerZero and confirmed independently by Mandiant and CrowdStrike.
  2. #34[disputed][awaiting moderator]in the timeline
    Arbitrum Security Council coordinates with law enforcement to freeze over 30,000 ETH of attacker downstream funds.
    reviewerKelpDAO's multisig paused core contracts ~46 minutes after the drain, blocking a second forged packet, and the Arbitrum Security Council froze over 30,000 ETH of attacker funds — both on 2026-04-18.The multisig-pause portion of this entry is correctly dated to April 18, but the Arbitrum freeze did not occur until approximately April 20-21, roughly two to three days later. Bundling both events under the 2026-04-18 date misdates the freeze; it should be recorded as a separate timeline entry dated 2026-04-20 or 2026-04-21.

unverifiable

2 claims

No source the reviewer could reach confirms or contradicts the claim.

  1. #3[unverifiable][awaiting moderator]in section: Background and Protocol Overview
    At the time of the April 2026 incident, LayerZero V2 maintained a total value locked of approximately $7.2 billion across connected protocols, including Ethena's USDe, Wrapped Bitcoin, USDT0, and various restaking derivatives.
    reviewerAt the time of the incident, LayerZero V2 maintained a TVL of approximately $7.2 billion across connected protocols.Could not independently verify the precise $7.2 billion figure via DeFiLlama or search; the general scale (billions in TVL, multiple named protocols) is plausible and uncontested but the specific number is unconfirmed.
  2. #37[unverifiable][awaiting moderator]in the timeline
    Chainalysis publishes detailed on-chain analysis of the KelpDAO bridge exploit. OpenZeppelin publishes post-mortem confirming zero smart contract vulnerabilities; failure attributed entirely to off-chain infrastructure and configuration policy.
    reviewerOn 2026-04-23, Chainalysis published on-chain analysis and OpenZeppelin published its post-mortem confirming zero smart contract vulnerabilities.OpenZeppelin's April 23 publish date is corroborated, but the Chainalysis publish date bundled into the same entry could not be reliably confirmed as April 23 specifically; weak signals suggest it may have been published or last updated later.

partially supported

1 claim

The cited evidence supports part of the claim but not all of it.

  1. #17[partially supported][awaiting moderator]in section: DVN Configuration Policy: Systemic Risk and Dispute
    KelpDAO cited Telegram screenshots showing a LayerZero team member stating 'No problem on using defaults either' regarding the DVN setup.
    reviewerKelpDAO cited Telegram screenshots showing a LayerZero team member stating 'No problem on using defaults either' regarding the DVN setup.The screenshot and quote are accurately reported as KelpDAO's claim, but the cited source's own caveat about lack of independent authentication is omitted, giving the claim more certainty on the page than the source itself asserts.

confirmed

36 claims

The cited evidence supports the claim as written.

  1. #1[confirmed][no action needed]in the summary
    On April 18, 2026, a $292 million exploit drained KelpDAO's rsETH bridge after LayerZero's Decentralized Verifier Network (DVN) infrastructure was compromised via a 1-of-1 single-node configuration, enabling attackers attributed to North Korea's Lazarus Group (TraderTraitor/UNC4899) to forge a cross-chain message without any redundancy check.
    reviewerOn April 18, 2026, a $292 million exploit drained KelpDAO's rsETH bridge after LayerZero's DVN infrastructure was compromised via a 1-of-1 single-node configuration, enabling Lazarus/TraderTraitor to forge a cross-chain message without redundancy check.Core facts corroborated across LayerZero's own incident report and multiple tier-1 outlets.
  2. #2[confirmed][no action needed]in the summary
    LayerZero subsequently acknowledged it 'made a mistake' in allowing its DVN to operate in 1/1 mode for high-value assets and announced it would no longer service such configurations, while a dispute with KelpDAO over responsibility for the configuration remains unresolved.
    reviewerLayerZero subsequently acknowledged it 'made a mistake' in allowing 1/1 DVN operation for high-value assets and will no longer service such configurations; the responsibility dispute with KelpDAO remains unresolved.Quote and policy reversal independently confirmed; the KelpDAO dispute over responsibility was still contested in the most recent reporting found.
  3. #4[confirmed][no action needed]in section: Background and Protocol Overview
    including Ethena's USDe, Wrapped Bitcoin, USDT0, and various restaking derivatives
    reviewerLayerZero underpins Ethena's USDe, Wrapped Bitcoin, USDT0, and restaking derivatives among other protocols.Named protocols independently corroborated via multiple secondary reports on post-exploit TVL migration.
  4. #5[confirmed][no action needed]in section: The April 2026 KelpDAO Bridge Exploit
    On April 18, 2026, attackers drained 116,500 rsETH (approximately $292 million) from KelpDAO's LayerZero-powered rsETH bridge, making it the largest DeFi exploit of 2026.
    reviewer116,500 rsETH (~$292 million) was drained from KelpDAO's bridge on April 18, 2026, making it the largest DeFi exploit of 2026, with the failure entirely in off-chain infrastructure per OpenZeppelin.Widely and consistently corroborated across tier-1 and tier-2 sources.
  5. #6[confirmed][no action needed]in section: The April 2026 KelpDAO Bridge Exploit
    OpenZeppelin's post-mortem confirmed zero smart contract bugs; the contracts 'performed exactly as written.'
    reviewerOpenZeppelin's post-mortem confirmed zero smart contract bugs; the contracts 'performed exactly as written.'Substance and phrasing closely match the OpenZeppelin post-mortem.
  6. #7[confirmed][no action needed]in section: The April 2026 KelpDAO Bridge Exploit
    Attackers submitted a fabricated cross-chain message claiming 116,500 rsETH had been locked on the source chain (Unichain) — no corresponding source transaction existed.
    reviewerAttackers submitted a fabricated cross-chain message claiming rsETH had been locked on Unichain, with no corresponding source transaction.Corroborated by multiple independent technical write-ups (Blockaid, DarkNavy, Hypernative, Chainalysis).
  7. #8[confirmed][no action needed]in section: The April 2026 KelpDAO Bridge Exploit
    KelpDAO's emergency multisig paused core contracts approximately 46 minutes after the initial drain, blocking a second forged packet targeting an additional 40,000 rsETH (~$100 million).
    reviewerKelpDAO's emergency multisig paused core contracts ~46 minutes after the drain, blocking a second forged packet targeting 40,000 rsETH (~$100M).46-minute gap and second blocked packet corroborated by multiple sources.
  8. #9[confirmed][no action needed]in section: The April 2026 KelpDAO Bridge Exploit
    The attacker deposited the stolen rsETH into Aave V3 as collateral to borrow approximately 126,000 WETH, creating an estimated $123–230 million in bad debt across Aave lending pools on five chains.
    reviewerThe attacker deposited stolen rsETH into Aave V3, borrowed ~126,000 WETH, creating $123–230 million in bad debt across five chains, with WETH pools reaching 100% utilization.126,000 WETH figure and bad debt range are both independently corroborated, though estimates in circulation ranged as low as $177M (KuCoin's own headline figure) to as high as $230M depending on methodology — the page's range captures this spread reasonably.
  9. #10[confirmed][no action needed]in section: The April 2026 KelpDAO Bridge Exploit
    A coordinated recovery effort called 'DeFi United' was subsequently formed by Aave service providers, KelpDAO, Ether.fi, LayerZero, and Mantle to restore rsETH's backing.
    reviewerA coordinated recovery effort called 'DeFi United' was formed by Aave service providers, KelpDAO, Ether.fi, LayerZero, and Mantle to restore rsETH's backing.Coalition and purpose confirmed; the page's member list is a subset of the full roster reported elsewhere (e.g. Lido DAO also participated) but this is an omission, not an inaccuracy.
  10. #11[confirmed][no action needed]in section: Attack Vector: Social Engineering and RPC Node Compromise
    According to LayerZero's published incident report, the attack began on March 6, 2026 — over six weeks before the April 18 drain — when an attacker socially engineered a LayerZero Labs developer to harvest session keys and gain access to LayerZero's RPC cloud environment.
    reviewerThe attack began March 6, 2026 when a LayerZero Labs developer was socially engineered to harvest session keys, giving access to LayerZero's RPC cloud environment.Directly confirmed against the primary cited source.
  11. #12[confirmed][no action needed]in section: Attack Vector: Social Engineering and RPC Node Compromise
    On the day of the exploit, the attacker simultaneously executed a Denial of Service (DoS) attack against an external RPC provider, forcing the DVN signing service to rely exclusively on two compromised internal nodes.
    reviewerThe attacker executed a DoS attack against an external RPC provider, forcing the DVN signing service to rely exclusively on two compromised internal nodes.Mechanism confirmed directly against LayerZero's own incident report.
  12. #14[confirmed][no action needed]in section: DVN Configuration Policy: Systemic Risk and Dispute
    A Dune Analytics post-incident analysis found that 47% of active LayerZero OApp contracts (approximately 1,250 applications) were using the same 1-of-1 configuration, with combined exposure exceeding $4.5 billion.
    reviewerA Dune Analytics post-incident analysis found 47% of active LayerZero OApp contracts (~1,250 applications) used 1-of-1 DVN configuration, with combined exposure exceeding $4.5 billion.Figures independently corroborated with precise arithmetic match.
  13. #15[confirmed][no action needed]in section: DVN Configuration Policy: Systemic Risk and Dispute
    LayerZero's April 19, 2026 incident statement asserted that the 1-of-1 setup 'directly contradicts' its recommended multi-DVN model and represents application-level misconfiguration outside protocol scope.
    reviewerLayerZero's April 19, 2026 incident statement asserted the 1-of-1 setup 'directly contradicts' its recommended multi-DVN model.Exact quoted language confirmed against the primary source.
  14. #16[confirmed][no action needed]in section: DVN Configuration Policy: Systemic Risk and Dispute
    CEO Bryan Pellegrino published on-chain evidence purporting to show KelpDAO had originally deployed with a multi-DVN setup (LayerZero Labs plus Google) before allegedly manually downgrading to 1-of-1 on April 1, 2024.
    reviewerCEO Bryan Pellegrino published on-chain evidence showing KelpDAO originally deployed multi-DVN (LayerZero Labs + Google) before manually downgrading to 1-of-1 on April 1, 2024; KelpDAO disputed this.Downgrade claim, date, and prior configuration (LayerZero Labs + Google) all independently corroborated.
  15. #18[confirmed][no action needed]in section: DVN Configuration Policy: Systemic Risk and Dispute
    Somraaj later wrote: 'My bug bounty: not a vuln, requires all DVNs. Their deployment: removes the all part. Hackers: collects $295M bounty instead.'
    reviewerSecurity researcher Sujith Somraaj, a prior LayerZero auditor, submitted a rejected bug bounty describing the identical attack pattern, later writing about a '$295M bounty' collected by hackers instead.Quote, attribution, and context independently confirmed.
  16. #19[confirmed][no action needed]in section: LayerZero's Admissions and Policy Changes
    LayerZero stated: 'We made a mistake by allowing our DVN to act as a 1/1 DVN for high-value transactions.'
    reviewerLayerZero stated: 'We made a mistake by allowing our DVN to act as a 1/1 DVN for high-value transactions.'Verbatim quote confirmed.
  17. #20[confirmed][no action needed]in section: LayerZero's Admissions and Policy Changes
    A separate internal security lapse was also disclosed: a multisig signer had improperly used company hardware for personal trading activity approximately three and a half years prior.
    reviewerA multisig signer had improperly used company hardware for personal trading approximately three and a half years prior; the signer was removed and wallets rotated.Directly confirmed, including the specific 'three and a half years' figure.
  18. #21[confirmed][no action needed]in section: LayerZero's Admissions and Policy Changes
    Policy changes announced by LayerZero include: (1) the LayerZero DVN will no longer service any 1/1 configuration; (2) all default pathways are migrating to 5/5 verification where feasible, or minimum 3/3 where only three DVNs operate; (3) the company built custom multisig technology called 'OneSig' and added localized anomaly detection software to signing devices.
    reviewerPolicy changes: LayerZero DVN will no longer service 1/1 configurations; default pathways migrate to 5/5 or minimum 3/3; the company built custom multisig technology 'OneSig' with anomaly detection.All three policy changes independently confirmed.
  19. #22[confirmed][no action needed]in section: Market and Ecosystem Impact
    KelpDAO publicly shifted its rsETH bridge infrastructure to Chainlink CCIP.
    reviewerKelpDAO publicly shifted its rsETH bridge infrastructure to Chainlink CCIP.Directly confirmed by headline source.
  20. #23[confirmed][no action needed]in section: Market and Ecosystem Impact
    Solv Protocol, which managed over $700 million in tokenized Bitcoin (SolvBTC and xSolvBTC), announced a full migration to Chainlink CCIP, discontinuing LayerZero support across Corn, Berachain, Rootstock, and TAC networks.
    reviewerSolv Protocol, managing over $700 million in tokenized Bitcoin, announced full migration to Chainlink CCIP, discontinuing LayerZero support across Corn, Berachain, Rootstock, and TAC.Dollar figure and migration confirmed by the directly cited tier-1 source; a secondary source's slightly lower TVL figure reflects a different measurement, not a contradiction.
  21. #24[confirmed][no action needed]in section: Market and Ecosystem Impact
    Additional protocols including Re and Kraken Bitcoin also joined the migration.
    reviewerAdditional protocols including Re and Kraken Bitcoin also joined the migration to Chainlink.Kraken migration independently confirmed; Re's inclusion is consistent with AMBCrypto's TVL breakdown of departing protocols.
  22. #25[confirmed][no action needed]in section: Market and Ecosystem Impact
    Chainlink CCIP reportedly gained over $2.5 billion in TVL from protocols departing LayerZero.
    reviewerChainlink CCIP reportedly gained over $2.5 billion in TVL from protocols departing LayerZero.Directly confirmed by headline source.
  23. #26[confirmed][no action needed]in section: Market and Ecosystem Impact
    LayerZero's total protocol TVL contracted by approximately $2 billion as a result of these migrations.
    reviewerLayerZero's total protocol TVL contracted by approximately $2 billion as a result of these migrations.Confirmed directly; the shortlink URL used in the page resolves correctly to the article (no link rot).
  24. #27[confirmed][no action needed]in section: Market and Ecosystem Impact
    The ZRO token fell approximately 28% over the 30-day period following the exploit, compounded by a concurrent $40.4 million token unlock.
    reviewerThe ZRO token fell approximately 28% over the 30-day period following the exploit, compounded by a concurrent $40.4 million token unlock.Both figures (28% decline, $40.4M unlock) independently confirmed.
  25. #28[confirmed][no action needed]in section: Market and Ecosystem Impact
    The Arbitrum Security Council, coordinating with law enforcement, froze over 30,000 ETH of the attacker's downstream funds.
    reviewerThe Arbitrum Security Council, coordinating with law enforcement, froze over 30,000 ETH of the attacker's downstream funds.Confirmed as undated prose in the ecosystem-impact section; note the freeze actually took place ~April 20-21, a few days after the exploit (see the separate timeline finding below).
  26. #29[confirmed][no action needed]in section: Broader Audit and Industry Implications
    OpenZeppelin's post-mortem identified a systemic gap in the DeFi security model: traditional smart contract audits do not assess third-party integration configurations, infrastructure dependencies, or off-chain component reliability.
    reviewerOpenZeppelin's post-mortem identified a systemic gap: audits do not assess third-party integration configurations or off-chain infrastructure reliability.Framing accurately reflects the cited source's thesis.
  27. #30[confirmed][no action needed]in the timeline
    KelpDAO and LayerZero enter partnership. KelpDAO alleges LayerZero personnel explicitly confirmed the 1-of-1 DVN default configuration was appropriate during initial L2 expansion discussions.
    reviewerIn 2024, KelpDAO and LayerZero entered a partnership; KelpDAO alleges LayerZero personnel confirmed the 1-of-1 DVN default was appropriate during initial L2 expansion discussions.Both the partnership start (early 2024) and the properly-attributed nature of the claim (framed as KelpDAO's allegation, not established fact) are accurate.
  28. #31[confirmed][no action needed]in the timeline
    LayerZero CEO Bryan Pellegrino alleges KelpDAO manually downgraded its DVN configuration from a multi-DVN setup (LayerZero Labs + Google) to a 1-of-1 configuration, citing on-chain evidence. KelpDAO disputes this account.
    reviewerIn April 2024, Pellegrino alleges KelpDAO manually downgraded its DVN configuration from multi-DVN to 1-of-1; KelpDAO disputes this.Matches earlier verified claim on the same underlying fact.
  29. #32[confirmed][no action needed]in the timeline
    Attack initiation: an attacker socially engineers a LayerZero Labs developer to harvest session keys and gain access to LayerZero's internal RPC cloud environment. Malware is deployed to poison internal RPC nodes while maintaining normal responses to monitoring systems.
    reviewerAttack initiation on 2026-03-06: social engineering of a LayerZero Labs developer, RPC cloud access, malware poisoning internal RPC nodes.Directly confirmed against primary source.
  30. #33[confirmed][no action needed]in the timeline
    Exploit executed at approximately 17:35 UTC. Attacker submits a forged LayerZero packet claiming to originate from KelpDAO's Unichain deployment. The compromised 1-of-1 DVN attests to the fraudulent message. 116,500 rsETH (~$292 million) is released to the attacker. Attacker deposits stolen rsETH into Aave V3, borrows approximately $236 million in WETH, creating $123–230 million in bad debt.
    reviewerExploit executed 2026-04-18 at ~17:35 UTC: forged packet from Unichain, compromised DVN attests, 116,500 rsETH released; attacker borrows ~$236M WETH on Aave, creating $123-230M bad debt.All figures in this entry independently confirmed and internally consistent with the 46-minute-later multisig freeze at 18:21 UTC.
  31. #35[confirmed][no action needed]in the timeline
    LayerZero publishes an incident statement attributing the exploit to KelpDAO's 1-of-1 DVN configuration, asserting it 'directly contradicts' recommended multi-DVN best practices. LayerZero attributes the attack with preliminary confidence to North Korea's Lazarus Group (TraderTraitor/UNC4899).
    reviewerOn 2026-04-19, LayerZero published an incident statement blaming KelpDAO's configuration and attributing the attack with preliminary confidence to Lazarus/TraderTraitor.Confirmed; note LayerZero's incident statement was published April 19-20 depending on source (minor rounding across outlets, not a substantive discrepancy).
  32. #36[confirmed][no action needed]in the timeline
    KelpDAO publicly disputes LayerZero's framing. KelpDAO asserts the 1-of-1 DVN setup reflected LayerZero's documented default and that LayerZero personnel explicitly approved the configuration. KelpDAO announces it will shift rsETH bridge infrastructure to Chainlink CCIP.
    reviewerOn 2026-04-20, KelpDAO publicly disputed LayerZero's framing, asserted the default configuration was approved, and announced its move to Chainlink CCIP.Confirmed.
  33. #38[confirmed][no action needed]in the timeline
    KelpDAO provides additional documentation of its allegations, including Telegram screenshots showing a LayerZero team member stating 'No problem on using defaults either' regarding the DVN setup. KelpDAO also surfaces the rejected bug bounty report by security researcher Sujith Somraaj, a prior LayerZero auditor, who had described the identical attack vector.
    reviewerOn 2026-05-05, KelpDAO provided additional documentation including Telegram screenshots and surfaced Somraaj's rejected bug bounty report.Confirmed; note the same 'unauthenticated screenshot' caveat identified in the sections[3] finding applies here too, but the timeline entry is a neutral factual description of what KelpDAO submitted rather than an assertion of the underlying claim's truth.
  34. #39[confirmed][no action needed]in the timeline
    Solv Protocol announces migration of over $700 million in SolvBTC and xSolvBTC tokenized Bitcoin infrastructure from LayerZero to Chainlink CCIP, discontinuing LayerZero support across Corn, Berachain, Rootstock, and TAC networks.
    reviewerOn 2026-05-07, Solv Protocol announced migration of over $700 million in tokenized Bitcoin from LayerZero to Chainlink CCIP.Confirmed.
  35. #40[confirmed][no action needed]in the timeline
    LayerZero publicly admits fault, stating 'We made a mistake by allowing our DVN to act as a 1/1 DVN for high-value transactions.' LayerZero announces it will no longer service 1/1 DVN configurations, will migrate default pathways to 5/5 or minimum 3/3 verification, and has built custom multisig technology called OneSig. A separate disclosure reveals a prior internal security lapse involving a multisig holder using company hardware for personal trades.
    reviewerOn 2026-05-09, LayerZero publicly admitted fault, quoted its 'made a mistake' statement, announced policy changes and OneSig, and disclosed the multisig personal-trading lapse.Consistent with the earlier verified findings on the same facts.
  36. #41[confirmed][no action needed]in the timeline
    LayerZero publishes full incident report. Mandiant, CrowdStrike, and independent researchers are cited confirming attribution to TraderTraitor (UNC4899). Chainalysis updates its analysis with additional findings.
    reviewerOn 2026-05-18, LayerZero published its full incident report, with Mandiant, CrowdStrike and independent researchers cited confirming TraderTraitor (UNC4899) attribution, and Chainalysis updating its analysis.This entry is worded more cautiously than sections[2] (it attributes confirmation to 'Mandiant, CrowdStrike, and independent researchers' rather than naming Chainalysis as an independent confirmer), and is consistent with what was independently verified.
How this fits together. The reviewer reads the published page and its cited sources and records one finding per claim. A human moderator decides whether each proposed correction is applied; those decisions, and the score changes they cause, appear in the audit log. Earlier review runs are not shown here; only the latest reflects the page as it stands.