A new dashboard from Dune Analytics has uncovered a sobering reality across the Layerzero ecosystem: nearly half of all omnichain applications (OApps) are operating with the lowest possible security threshold, raising fresh concerns about the resilience of cross-chain infrastructure.
Analyzing approximately 2,665 unique OApp contracts over the past 90 days, the data focuses on how these applications configure Layerzero's Decentralized Verifier Network (DVN). The findings show that 47% of OApps use a 1-of-1 DVN setup—meaning only a single independent verifier is required to validate cross-chain messages. This is the minimum configuration allowed by the protocol. Another 45% opt for a 2-of-2 configuration, while just about 5% employ more robust setups requiring three or more independent verifiers.
The KelpDAO Exploit: A Costly Lesson in Minimal Security
The release of this data comes in the aftermath of the KelpDAO exploit, which resulted in the loss of nearly $300 million from its rsETH product and triggered a broader DeFi liquidity crisis that saw approximately $14 billion vanish from the ecosystem's total value locked. According to Dune's dashboard, KelpDAO's rsETH contract falls squarely within the 1-of-1 DVN category.
This incident has become a case study in how minimal security configurations can become single points of failure in cross-chain operations. While Layerzero's DVN model offers developers flexibility to balance cost and performance, the 1-of-1 setup introduces a critical vulnerability: if the single verifier is compromised or behaves maliciously, the entire message can be tampered with.
The Trade-Off Between Flexibility and Security
Layerzero's design philosophy places much of the security decision-making in the hands of application developers. The DVN framework allows from 1-of-1 to multi-verifier setups, but Dune's data indicates that the vast majority of projects choose the path of least resistance. Higher configurations (e.g., 3-of-3 or weighted multi-verifier models) improve redundancy and trust distribution but come with increased operational complexity and costs.
Dune's dashboard does not assign security scores to projects, as the firm notes that DVN count alone is not a complete risk indicator. Other factors—such as the independence of verifier operators, optional security thresholds, and the value of assets being bridged—also play a crucial role. Nevertheless, the prevalence of minimal configurations suggests that many developers prioritize simplicity and low cost over robust security.
Will Stricter Scrutiny Drive Upgrade?
As the KelpDAO exploit continues to reverberate across DeFi markets, the pressure on cross-chain protocols to improve security standards is mounting. Currently, only about 5% of Layerzero OApps use three or more DVNs, but this figure may rise as both users and regulators demand greater transparency and protection.
For end-users, understanding the security configuration of the cross-chain applications they interact with could become as important as evaluating smart contract audits. The Dune data serves as a stark reminder: in the race to scale cross-chain functionality, foundational security must not be an afterthought.

