EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

Suspected LayerZero actuator wallet was compromised and $2.1 million was stolen across the chain

2026-07-17 00:12:09
Bookmark

LayerZero Executor wallet is suspected to have been compromised, resulting in cross-chain losses of approximately US$2.1 million.

The wallet used by LayerZero's Executor service may have been compromised, involving multiple networks. About US$2.1 million in assets were transferred and integrated into Ethereum. It was revealed that the attackers ended up holding approximately 955 ETH (worth approximately $1.78 million) and approximately $322,000 in USDC, and the stolen assets were routed through Stargate and Relay. These transfers point to a cross-chain fund collection operation rather than a new type of verified message exploit, and the source of wallet access has not yet been confirmed.

There is currently no evidence that LayerZero's message contracts, endpoints or decentralized verifier network have been compromised. The affected addresses appear to be related to the execution infrastructure, which maintains native Gas balances on supported chains to pass verified messages on the target chain.

The executor role limits the direct impact of the protocol.

The LayerZero Executor automatically completes the final delivery of cross-chain messages by calling lzReceive() or lzCompose() after the message passes through its configured verification process. These endpoint functions are unlicensed after verification is complete, allowing other executors or users to complete delivery if the specified service fails. An intrusion into the Executor funds wallet could expose assets held by the wallet and interrupt automatic delivery until the balance or key is replaced. But with this behavior alone, an attacker cannot forge cross-chain messages or change the verifier collection.

LayerZero once described its Executor as a Gas abstraction and execution service that plays no role in determining whether a message is valid. The company previously stated that Executor failures will cause delivery or activity issues, but users or other unlicensed executors can still manually submit verified transactions.

Stargate and Relay route stolen assets

The attacker used two established cross-link routes to transfer assets from multiple chains to Ethereum. Stargate provides native asset liquidity between LayerZero-connected networks, while Relay uses cross-chain intentions and solvers to complete transfers on the target chain before settling source chain orders. Using these two services does not indicate that Stargate or Relay has been compromised. These agreements appear to only serve as transfer routes after assets have left the suspicious Executor wallet. During the initial fund tracking, no individual losses were found to have been suffered by their liquidity pools or contracts.

Previous KelpDAO incident exposed another part of the infrastructure

Prior to this suspected wallet intrusion, the KelpDAO incident exposed another part of LayerZero's infrastructure. In that attack, compromised RPC infrastructure provided false source chain information to a single validator setup, resulting in the release of approximately $292 million in rsETH. Executor performs the delivery after the message has been accepted as verified. After the KelpDAO failure, Lombard moved more than $1 billion in bitcoin-backed assets from the LayerZero infrastructure, while Virtuals moved approximately $700 million in VIRTUAL tokens to Chainlink CCIP.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP