defirisk.co
rubric v1.7.0

LayerZero OFT DVN config (count, threshold, diversity)

A cross-chain & bridge factor in the v1.7.0 rubric. Measured per protocol on a s cadence.

Methodology how we score #

**What this measures**

This factor assesses the LayerZero OFT (Omnichain Fungible Token) adapter's DVN (Decentralized Verifier Network) configuration: how many DVNs are required to attest a cross-chain message, what threshold of those DVNs must agree (k-of-N), and whether the listed DVN operators are independent entities or the same operator running multiple endpoints. Cat 10 applies only to bridge-touching protocols; non-bridge protocols show this factor as N/A. The 1-of-1 DVN configuration is the catastrophic edge — a single DVN can unilaterally attest to a forged inbound message and trigger an unbacked mint on the destination chain.

**Why it matters**

LayerZero OFT is now the dominant cross-chain token-bridging primitive on EVM L2s, but its security guarantees are a function of how the OFT adapter is configured by the deploying protocol — not an intrinsic property of LayerZero itself. A 1/1 DVN configuration means there is no honest-majority assumption: a single compromised, captured, or buggy DVN can forge an `lzReceive` payload and the destination chain will accept the mint as legitimate. Threshold without operator diversity is similarly weak: 2-of-3 DVNs all run by the same operator collapses to single-operator trust at validator level, even though the on-chain config looks redundant.

**Green / Yellow / Red**

Green is ≥3 independent DVN operators with threshold ≥2 — a meaningful k-of-N attestation set. Yellow is 2 DVNs with threshold 2, or any threshold-2 configuration where operators are not fully independent. Red is the 1/1 configuration: a single DVN with threshold 1, where any single attestation suffices to mint on the destination chain.

**Common gray cases**

The protocol does not deploy a LayerZero OFT adapter at all (factor is N/A). On-chain DVN registry reads are inconclusive when the adapter uses a custom DVN list that is not standard-registered, requiring source inspection.

**Notable historical examples**

No cross-hacked incidents currently linked in database for this factor. The most-cited industry incident is **Kelp DAO** (Apr 2026, $292M loss), where a 1-of-1 DVN configuration on the rsETH OFT adapter allowed a single forged message to mint unbacked rsETH on a destination chain. Aave governance forum publicly flagged the 1/1 DVN risk approximately 15 months prior to the exploit, making this a structural risk that was visible on-chain and publicly debated long before failure.

Measurement what to look for #

For any LayerZero OFT adapter, read the DVN configuration: count of DVNs, k-of-N threshold, and operator diversity (independent operators vs same-operator multi-DVN).

Data & output #

Data source
LayerZero endpoint contract `getConfig()` for the OFT adapter address + LayerZero DVN registry on-chain reads
Output format
Green / Yellow / Red
Evidence artifact
OFT adapter address + DVN addresses list + threshold k + operator-diversity assessment
Confidence signal
green = ≥3 independent DVN operators with threshold ≥2; yellow = 2 DVNs or threshold=2 but operators not fully independent; red = 1/1 DVN configuration (any single DVN can approve); gray = protocol does not use LayerZero OFT (N/A)

Scored protocols 80 carry this factor #

Protocol RD-F-179
Aave v3 ethereum yellow Across Protocol ethereum yellow Aerodrome Finance base not_applicable Axelar Network ethereum not_applicable Babylon Protocol bitcoin not_applicable Balancer (v2 + v3) ethereum not_applicable Beefy Finance ethereum not_applicable BENQI avalanche not_applicable BlackRock USD Institutional Digital Liquidity Fund (BUIDL) ethereum not_applicable Cap (cUSD / stcUSD) ethereum yellow Centrifuge ethereum gray Chainlink CCIP ethereum not_applicable Circle USYC binance not_applicable Compound V3 (Comet) ethereum not_applicable Concrete ethereum gray Convex Finance ethereum not_applicable crvUSD (Curve Stablecoin) ethereum not_applicable Curve Finance ethereum yellow deBridge ethereum not_applicable Dolomite ethereum not_applicable dYdX v4 (dYdX Chain) dydx not_applicable EigenLayer ethereum not_applicable Ethena ethereum yellow ether.fi ethereum yellow Euler V2 ethereum not_applicable Falcon Finance ethereum not_applicable Fluid ethereum gray Frax Finance ethereum yellow GMX v2 (GMX Synthetics) arbitrum not_applicable Hyperlane ethereum not_applicable Hyperliquid arbitrum gray Jito solana not_applicable Jupiter solana not_applicable Jupiter Perpetual Exchange solana not_applicable JustLend DAO tron not_applicable Kamino Lend solana not_applicable Kinetiq hyperliquid not_applicable Lido ethereum yellow Liquid Collective (LsETH) ethereum not_applicable Liquity V1 + V2 (LUSD / BOLD) ethereum not_applicable Lista DAO bsc yellow Lombard Finance ethereum yellow M^0 ethereum not_applicable Maple Finance ethereum yellow Marinade Finance solana not_applicable Meteora solana not_applicable mETH Protocol ethereum gray Midas ethereum not_assessed Morpho V1 (Morpho Blue + MetaMorpho) ethereum not_applicable Multipli ethereum not_applicable Ondo Finance ethereum yellow OpenEden ethereum not_applicable Orca solana not_applicable PancakeSwap bsc not_applicable Pendle Finance ethereum yellow Polymarket polygon not_applicable QuickSwap polygon not_applicable Raydium solana not_applicable Rocket Pool ethereum not_applicable Sanctum solana not_applicable Save (formerly Solend) solana not_applicable Sky Lending (formerly MakerDAO) ethereum yellow Spark Protocol ethereum yellow Spiko stellar not_applicable Stake DAO ethereum not_applicable StakeWise v3 ethereum not_applicable Stargate Finance ethereum gray stHYPE (Valantis Labs) hyperliquid not_applicable SUNSwap (sun.io) tron not_applicable Superstate ethereum not_applicable Sushi (SushiSwap) — v2 + v3 + Trident + BentoBox/Kashi + SushiXSwap ethereum not_applicable Symbiotic ethereum not_applicable Synapse Protocol ethereum not_applicable Uniswap (v2 + v3) ethereum not_applicable USDD (Decentralized USD) tron not_applicable Usual (USD0 / bUSD0 / USUAL) ethereum yellow Veda (BoringVault) ethereum gray Venus Protocol bsc yellow Wormhole ethereum gray Yearn Finance ethereum not_applicable

Linked hacks no historical incidents linked #

No historical incidents are linked to this factor.
rubric_version v1.7.0 factor RD-F-179 category 10 carried 80 critical no