LayerZero's $3B+ in OFTs exposed to compromise risk via vulnerable default library contract; security debate erupted in ETHSecurity community.
Security & Exploits ·
A security concern emerged around LayerZero's OFT (Omnichain Fungible Token) contracts after a debate in the ETHSecurity Community highlighted risks in the protocol's default library contract. Over $3 billion in OFTs were recently exposed to potential compromise because LayerZero Labs could upgrade the contract instantly without a timelock, enabling message forgery—similar to the rsETH incident. Major projects including Ethena and EtherFi were still using this default library as recently as a few weeks ago, with $178 million in value remaining exposed across projects relying on it.
The vulnerability exists independent of malicious intent; the concern centers on LayerZero Labs' operational security practices. Onchain activity shows multisig signers engaged in non-multisig transactions including memecoin trading, DEX swaps, and bridging—activities that suggest production keys were connected to web-accessible platforms rather than kept isolated for signing only. This pattern of key management raises questions about exposure to phishing and compromise, particularly given that LayerZero Labs has experienced prior security incidents.
What remains unresolved is whether affected projects have since migrated away from the default library contract and whether LayerZero Labs plans to implement a timelock mechanism. The debate also did not produce a clear timeline for when the specific vulnerability window closed or what additional safeguards, if any, are now in place.