Fresh data from Dune Analytics suggests that a large share of the LayerZero ecosystem is still operating with the most basic validator setup available. The dashboard, which reviewed activity over the past 90 days, found that 47% of roughly 2,665 unique omnichain application (OApp) contracts use a 1-of-1 DVN configuration, the minimum threshold required to validate cross-chain messages. The findings have intensified discussion around how much security many cross-chain applications are actually choosing in production.
LayerZero’s architecture gives developers flexibility in how they configure its Decentralized Verifier Network, or DVN. That flexibility is often seen as a feature: teams can optimize for lower costs, faster operations, or more tailored trust assumptions. But the same design also means developers must actively make security trade-offs. Dune’s latest breakdown indicates that many projects continue to favor leaner setups, even as cross-chain risks become more visible across decentralized finance.
What the Dune Data Found
The analysis examined approximately 2,665 unique OApp contracts. Of those, 47% were configured with 1-of-1 DVN security, meaning only a single verifier is needed to confirm a cross-chain message. Another 45% used a 2-of-2 setup, while only about 5% relied on configurations with three or more independent verifiers.
Those numbers do not automatically translate into a complete security ranking. Dune did not assign scores to projects, and the report explicitly noted that DVN count alone does not fully define a protocol’s risk profile. Still, the distribution is notable because it shows how concentrated the ecosystem remains around the lowest and near-lowest configuration tiers. In practical terms, stronger redundancy appears to be the exception rather than the rule.
A 1-of-1 model offers the lowest possible barrier to operation, but it also introduces a potential single point of failure. If the lone verifier fails, is compromised, or behaves unexpectedly, the security assumptions behind message validation can break down much more easily than in a multi-verifier design. By contrast, requiring multiple independent verifiers spreads trust across more parties, though it can also increase cost and operational complexity.
KelpDAO Incident Brings Cross-Chain Risk Back Into Focus
The timing of the data matters. The Dune findings surfaced in the wake of the KelpDAO exploit, an event that renewed scrutiny of cross-chain infrastructure and protocol-level security choices. According to the report, KelpDAO’s rsETH product, which was affected in the incident, fell into the 1-of-1 DVN category.
That detail has helped sharpen the market conversation. While the existence of a minimal DVN setup does not by itself explain an exploit, it has reinforced broader concerns about whether lower-cost configurations may leave some protocols more exposed than developers or users fully appreciate. In a market where billions of dollars can move across chains, even seemingly technical design choices can become systemically important.
The report references growing concern over cross-chain vulnerabilities following recent exploits more generally. This context is crucial: as bridge and messaging layers become foundational to DeFi, the security of the infrastructure below the application layer increasingly matters to the entire ecosystem, not just to one project at a time.
Security Is More Than the Number of Verifiers
Even so, the Dune dashboard stops short of reducing risk to a single metric. The number of DVNs is only one part of the picture. Other elements matter as well, including the independence of verifier operators, optional security thresholds, and the amount and type of value being transferred across chains. A protocol with fewer verifiers but strong operational controls may present a different risk profile than one with a larger set of validators that are not truly independent.
This nuance is important for interpreting the findings responsibly. A 2-of-2 or 3-of-3 setup is not automatically secure in every context, just as a 1-of-1 setup is not automatically doomed. But from a structural standpoint, the prevalence of the most basic configuration suggests that many teams still prioritize simplicity and affordability over redundancy. That may be a rational choice for some lower-stakes applications, yet it becomes more controversial when larger pools of assets are involved.
In other words, Dune’s data is less a verdict than a snapshot of current developer behavior. It shows where security defaults are landing in practice, and those defaults currently skew toward minimalism.
The Trade-Off at the Heart of LayerZero’s Model
LayerZero’s DVN model is built around configurability. Developers can choose how many independent verifiers are required to confirm transactions and messages across chains. This flexibility can be useful because different applications have different needs. A smaller project may want to minimize overhead, while a protocol moving larger sums may prefer heavier verification and stronger trust distribution.
But flexibility in infrastructure often comes with a hidden cost: it pushes more responsibility onto builders. Rather than inheriting a single ecosystem-wide security standard, developers must decide how much resilience they want to pay for. As a result, standards can become uneven across the same network. Some teams may implement stronger assumptions from day one, while others may delay upgrades until risk becomes impossible to ignore.
The Dune data suggests that this dynamic is now visible at scale. If nearly half of applications are still running a 1-of-1 DVN model, then baseline security remains relatively light across a significant part of the LayerZero environment. That may reflect startup-stage pragmatism, but it also reveals where the ecosystem could face pressure if scrutiny continues to rise.
What the Findings May Mean for the Market
The immediate takeaway is not that LayerZero itself is inherently insecure, nor that every application using a basic DVN setup is unsafe. Rather, the data points to a broader reality in cross-chain finance: security standards are highly uneven, and configuration choices matter. As protocols expand across multiple chains and user expectations increase, those choices are likely to receive more public attention.
If recent incidents continue to shape sentiment, developers may face stronger incentives to adopt more robust configurations, especially in protocols that handle meaningful asset volumes. The fact that only about 5% of surveyed applications use three or more verifiers suggests there is considerable room for that shift to happen. Whether it does may depend on market pressure, insurance requirements, user awareness, and the cost of stronger redundancy.
For now, the Dune dashboard provides a valuable look into how cross-chain applications are currently secured in the real world. Its core message is straightforward: minimum-security configurations remain common across LayerZero apps, even as the industry becomes more sensitive to the risks of cross-chain design. In an ecosystem built on interoperability, that is a statistic likely to stay in focus.

