LayerZero Core executor wallet drained of $2.1 million across chains
Security & Exploits ·
A wallet tied to LayerZero's Core Executor infrastructure appears to have been compromised, with stolen funds moved onto Ethereum through bridging services.
The incident has produced a combined loss of $2.1M spread across several blockchains, according to a report circulating on X. After the initial theft, the attacker routed the assets to Ethereum using Stargate and Relay as bridging paths, consolidating the haul into a single-chain position.
At present, the compromised funds sit largely in ether, with the attacker holding 955 ETH worth roughly $1.78M alongside $322K in USDC. Three addresses have been flagged as holding or having handled the stolen assets: 0x47b44685eB5F99982d03F6A3d56b019692033543, 0xADC35eb2d028D741b0A97147882B23D2d885089B, and 0x9e4e1D9f223593AD51058Be898fFB3e7EC0EfB19.
Early analysis points to a key compromise as the likely root cause rather than a smart-contract flaw, though this characterization has not been formally confirmed by LayerZero. The suspicious activity was first flagged by CyversAlerts, and the episode is now being tracked across multiple independent reports, with three distinct sources covering the cluster and converging on the same $2.1M figure and asset breakdown.
What remains unclear is how the executor wallet's private key or signing infrastructure was accessed, whether additional wallets tied to LayerZero's executor network are affected, and whether any funds can be frozen or recovered given that the stolen assets have already been bridged and consolidated on Ethereum. No official statement from LayerZero confirming the compromise or outlining remediation steps has been referenced in the available reporting. Monitoring of the flagged addresses for further movement, along with any on-chain response from LayerZero or affected bridge protocols, will be the next indicators to watch.