LayerZero OFT adapters identified as at-risk due to reliance on single-source trust assumptions, similar to the KelpDAO exploit vector.
Security & Exploits ·
A security researcher has flagged LayerZero OFT (Omnichain Fungible Token) adapters as at-risk due to their reliance on a single data verification network provider without custom multi-signature thresholds. The concern mirrors the structural vulnerability that enabled the KelpDAO exploit, wherein a single point of trust was leveraged to forge packets for rsETH.
The risk stems from OFTs that inherited LayerZero's default Decentralized Verifier Network (DVN) configuration—a single LZ Labs DVN with no custom multi-sig override. Should the root cause of the KelpDAO incident prove to be a signer-side compromise rather than Kelp-specific misconfiguration, the same fault domain would theoretically expose any OFT on that default path to similar minting attacks. The researcher notes that most OFTs never customized their defaults, expanding the surface area significantly.
Actual exploitation would require additional conditions beyond a compromised signer, including liquid destination markets for the attacker to convert forged tokens. Not all flagged adapters face imminent risk, but the vulnerability remains present for any that have not added independent DVNs or adjusted threshold requirements.