A new analysis from Dune Analytics reveals that nearly half of all applications built on Layerzero are operating with the most basic security configuration, prompting concerns about the resilience of cross-chain infrastructure following recent high-profile exploits.
Key Findings: Lopsided Security Distribution
The report, which examined roughly 2,665 unique omnichain application (OApp) contracts over the past 90 days, found that 47% rely on a 1-of-1 Decentralized Verifier Network (DVN) setup — the minimum threshold required to validate cross-chain messages. Another 45% use a 2-of-2 configuration, while only about 5% employ three or more independent verifiers for enhanced security.
Layerzero’s DVN model gives developers the flexibility to decide how many verifiers must confirm a transaction across chains. While this allows applications to optimize for cost and speed, it also introduces a trade-off: a 1-of-1 configuration creates a single point of failure. If that single verifier becomes compromised or acts maliciously, all messages depending on it are at risk. Higher configurations distribute trust across multiple parties but increase operational complexity and transaction fees.
The Dune dashboard does not assign security scores, as the firm notes that “DVN count alone does not fully define a protocol’s risk profile.” Factors such as verifier operator independence, optional security thresholds, and asset values also matter. Nevertheless, the prevalence of minimal configurations suggests that many developers prioritize simplicity and cost over redundancy — a trend that security auditors warn could have systemic consequences.
The KelpDAO Wake-Up Call
KelpDAO’s rsETH product, which suffered a nearly $300 million exploit, falls squarely into the 1-of-1 DVN category. The attack disrupted lending markets and wiped out billions in DeFi total value locked shortly after the incident. Although technical details are still emerging, security researchers argue that a single-verifier architecture drastically lowers the barrier for attackers, who only need to compromise one point to execute cross-chain fraud.
Since the exploit, some Layerzero ecosystem projects have started evaluating upgrades to higher DVN configurations, but adoption remains slow. Data shows that only ~5% of OApps currently use 3 or more verifiers, a stark contrast to the rising frequency of cross-chain attacks across the industry.
Beyond the Numbers: Cost vs. Security Dilemma
Layerzero’s flexibility has been a key driver of its adoption, but the Dune data underscores a broader challenge in decentralized finance: when infrastructure shifts security decisions to individual developers, baseline standards often gravitate toward the minimum viable option. Projects with smaller budgets or tight time-to-market may view multi-verifier setups as unnecessary overhead — until an exploit proves otherwise.
The KelpDAO event has reignited debates about whether Layerzero should introduce minimum security requirements for high-value asset transfers, or whether the ecosystem can self-regulate through better tooling and education. Meanwhile, the Dune dashboard provides a transparent look at how different chains, assets, and categories of OApps configure their DVNs, allowing users to make more informed risk assessments.
Conclusion
As cross-chain bridges and messaging protocols handle hundreds of billions of dollars in value, security cannot remain an afterthought. The Dune data reveals a glaring gap between available security options and actual adoption. While Layerzero’s design empowers developers, it also places a heavy burden on them to anticipate threats. With attacks growing more sophisticated, the industry urgently needs clearer security standards and incentives for adopting multi-verifier configurations. Without action, the next exploit may not just drain millions — it could erode trust in the entire cross-chain ecosystem.

