LayerZero OFT DVN config (count, threshold, diversity)
Lombard Finance's assessment for RD-F-179 — scored yellow on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.
Evidence summary #
LayerZero OFT routes preemptively paused in April 2026 following KelpDAO exploit ($292M extracted from 1/1 DVN configuration compromise). LBTCOFTAdapter inherits EfficientRateLimitedOFTAdapter providing outflow rate limiting as an additional protection layer. Exact DVN count, threshold, and operator identities used before the pause are not publicly disclosed by Lombard. No active LayerZero cross-chain risk while routes are paused. Post-KelpDAO industry standard is minimum 2-of-N independent DVNs. Lombard has not publicly committed to a minimum DVN threshold for re-enablement. Proactive defensive posture (pausing before any incident) is a strong positive signal. Yellow: routes paused (positive); DVN configuration cannot be confirmed as non-1/1 from public sources; re-enablement commitment absent.
Sources #
- URLDeFi Prime — KelpDAO rsETH Exploit AnalysisKelpDAO rsETH exploit — 1/1 DVN compromise enabling forged mintsretrieved 2026-05-05
- Lombard OFT adapters sourceLombard OFT adapters directory — EfficientRateLimitedOFTAdapterretrieved 2026-05-05
- Lombard LBTCOFTAdapter sourceLBTCOFTAdapter.sol — LayerZero OFT adapter (paused)retrieved 2026-05-05
Methodology #
For any LayerZero OFT adapter, read the DVN configuration: count of DVNs, k-of-N threshold, and operator diversity (independent operators vs same-operator multi-DVN).
See the full factor methodology and distribution across all protocols →