LayerZero Executor wallet is suspected to have been compromised, resulting in cross-chain losses of approximately US$2.1 million.
The wallet used by LayerZero's Executor service may have been compromised, involving multiple networks. About US$2.1 million in assets were transferred and integrated into Ethereum. It was revealed that the attackers ended up holding approximately 955 ETH (worth approximately $1.78 million) and approximately $322,000 in USDC, and the stolen assets were routed through Stargate and Relay. These transfers point to a cross-chain fund collection operation rather than a new type of verified message exploit, and the source of wallet access has not yet been confirmed.
There is currently no evidence that LayerZero's message contracts, endpoints or decentralized verifier network have been compromised. The affected addresses appear to be related to the execution infrastructure, which maintains native Gas balances on supported chains to pass verified messages on the target chain.
The executor role limits the direct impact of the protocol.
The LayerZero Executor automatically completes the final delivery of cross-chain messages by calling lzReceive() or lzCompose() after the message passes through its configured verification process. These endpoint functions are unlicensed after verification is complete, allowing other executors or users to complete delivery if the specified service fails. An intrusion into the Executor funds wallet could expose assets held by the wallet and interrupt automatic delivery until the balance or key is replaced. But with this behavior alone, an attacker cannot forge cross-chain messages or change the verifier collection.
LayerZero once described its Executor as a Gas abstraction and execution service that plays no role in determining whether a message is valid. The company previously stated that Executor failures will cause delivery or activity issues, but users or other unlicensed executors can still manually submit verified transactions.
Stargate and Relay route stolen assets
The attacker used two established cross-link routes to transfer assets from multiple chains to Ethereum. Stargate provides native asset liquidity between LayerZero-connected networks, while Relay uses cross-chain intentions and solvers to complete transfers on the target chain before settling source chain orders. Using these two services does not indicate that Stargate or Relay has been compromised. These agreements appear to only serve as transfer routes after assets have left the suspicious Executor wallet. During the initial fund tracking, no individual losses were found to have been suffered by their liquidity pools or contracts.
Previous KelpDAO incident exposed another part of the infrastructure
Prior to this suspected wallet intrusion, the KelpDAO incident exposed another part of LayerZero's infrastructure. In that attack, compromised RPC infrastructure provided false source chain information to a single validator setup, resulting in the release of approximately $292 million in rsETH. Executor performs the delivery after the message has been accepted as verified. After the KelpDAO failure, Lombard moved more than $1 billion in bitcoin-backed assets from the LayerZero infrastructure, while Virtuals moved approximately $700 million in VIRTUAL tokens to Chainlink CCIP.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following
ETH
VIRTUAL