A recent analysis by Dune Analytics has shed light on the security posture of applications built on Layerzero, revealing that nearly half are operating with the weakest possible security settings. The data, which covers approximately 2,665 unique Omnichain Application (OApp) contracts over the past 90 days, shows that 47% of these apps use a “1-of-1” Decentralized Verifier Network (DVN) configuration — the minimum threshold required to validate cross-chain messages.
Another 45% of applications rely on a “2-of-2” setup, while only about 5% employ more robust configurations that require three or more independent verifiers. The findings come amid heightened scrutiny of cross-chain security following the KelpDAO exploit, which resulted in the loss of nearly $300 million and triggered a broader downturn in DeFi markets, with over $14 billion in total value drained from lending protocols.
KelpDAO’s rsETH Falls Into the Riskiest Category
According to Dune, KelpDAO’s rsETH product — the target of the attack — falls squarely within the 1-of-1 DVN category. This configuration requires only a single verifier to approve cross-chain transactions, creating a single point of failure. The exploit exposed how attackers can compromise one validator to drain funds across multiple chains, bypassing the security assumptions that projects often rely on.
Layerzero’s DVN model gives developers the flexibility to choose how many independent verifiers must confirm transactions, balancing security with cost and performance. However, the prevalence of minimal configurations suggests that many teams prioritize speed and lower operational expenses over redundancy. In practice, a 1-of-1 setup means the entire security of the cross-chain bridge hinges on the trustworthiness and robustness of a single operator.
Beyond DVN Count: A Complex Risk Landscape
The Dune dashboard provides a granular breakdown of how applications configure DVN parameters across different blockchains, asset types, and protocol categories. The analysis does not assign security scores, as the team notes that DVN count alone is not a complete indicator of risk. Other factors — such as the independence of verifier operators, optional security thresholds (e.g., additional signature requirements), and the total value being transferred — also play critical roles.
Despite these nuances, the overwhelming reliance on 1-of-1 configurations raises alarms across the industry. The flexibility that Layerzero offers to developers may inadvertently shift the burden of security decisions onto teams that lack the resources or expertise to implement robust safeguards. As a result, the cross-chain ecosystem is now facing a landscape where baseline security is the norm, even as the consequences of weak setups have become painfully visible.
Industry Response: Calls for Higher Standards
In the wake of the KelpDAO incident, several DeFi projects and security firms have called for Layerzero to enforce minimum DVN requirements or provide clearer guidance on recommended configurations. Some developers are experimenting with insurance pools to cover losses from single-verifier failures, while others are advocating for a default shift to 2-of-2 or higher setups for high-value bridges.
Dune’s data serves as a wake-up call: only 5% of applications currently use three or more verifiers, indicating that the vast majority of cross-chain dApps remain exposed to similar attack vectors. Without widespread adoption of stronger security configurations, the next successful exploit could be even more devastating.
In conclusion, while Layerzero’s DVN model offers valuable flexibility, the current state of application security is deeply concerning. The data underscores an urgent need for developers to reassess their security priorities and for the broader crypto community to establish baseline standards for cross-chain infrastructure. As the DeFi ecosystem continues to recover from the KelpDAO shock, one question remains: will more projects move beyond the bare minimum before the next attack?

