LayerZero executor wallets exploited for $2.4M across multiple chains
Executor wallets in LayerZero’s architecture are the components responsible for actually delivering messages between chains. They pick up a package on one chain and drop it off on another.
In April 2026, KelpDAO suffered a major breach linked to LayerZero infrastructure, in which approximately 116,500 rsETH, worth around $292 million at the time, was drained after attackers forged a cross-chain message by compromising a single-signer DVN role.
That attack was attributed to North Korea’s Lazarus Group. The KelpDAO breach also revealed a systemic configuration problem: nearly half of all LayerZero applications were still operating with what security researchers called a “1-of-1” DVN setup. That means one compromised verifier is all it takes to forge a valid message.
The KelpDAO incident triggered calls across the ecosystem for applications built on LayerZero to migrate toward multi-signer DVN configurations, which require more than one independent verifier to approve a message before it can be executed.
LayerZero’s architectural approach emphasizes configurability over a single canonical security model, giving applications control over their own risk parameters. The tradeoff is that misconfigured or under-secured applications become the weakest links.
Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.
You may also like
Will the AI Boom Repeat the Railroad Investment Bubble? Blackstone President: This Time Is Different
Canadian Dollar holds steady amid oil uncertainties, hawkish Fed sentiment
Morgan Stanley Interprets ECOC Conference: NPO Consensus Shifts to 2028 Implementation, Optical Devices Sold Out for 12-18 Months, These U.S. Stocks Benefit the Most
Morgan Stanley ECOC Quick Review: Full Speed Ahead—NPO to be implemented in 2028, InP substrate is the biggest bottleneck.

