A recent analysis by Dune Analytics has uncovered that nearly half of all applications built on Layerzero are operating with the most basic security settings, raising fresh concerns about cross-chain infrastructure vulnerabilities. The data comes in the wake of a major exploit targeting KelpDAO’s rsETH product, which itself relied on the weakest configuration.
Key Data Points
Over the past 90 days, Dune Analytics reviewed approximately 2,665 unique omnichain application (OApp) contracts that use Layerzero’s Decentralized Verifier Network (DVN). The findings show: 47% of these apps use a 1-of-1 DVN setup, meaning a single verifier is sufficient to validate cross-chain messages; 45% use a 2-of-2 configuration requiring two verifiers; and only about 5% employ three or more independent verifiers, offering stronger redundancy.
The DVN model gives developers flexibility to balance cost, performance, and security. However, the 1-of-1 configuration creates a single point of failure — if that verifier is compromised, all cross-chain messages it validates become vulnerable.
KelpDAO Exploit: A Wake-Up Call
Notably, KelpDAO’s rsETH product affected by the recent $300 million exploit was also configured as 1-of-1. The attacker exploited weaknesses in the cross-chain validation process, leading to massive losses. While DVN count alone does not fully determine risk — factors like verifier operator independence and asset value also matter — the prevalence of minimal configurations suggests many developers prioritize simplicity over security redundancy.
Industry Implications
The findings highlight a broader challenge in decentralized finance: infrastructure flexibility often pushes security-decisions down to application developers, resulting in uneven standards. As cross-chain attacks become more frequent, pressure is mounting for stricter default configurations. Industry observers expect that Layerzero and the wider ecosystem will push for at least 2-of-2 setups as a baseline, particularly for high-value assets.
“The data shows that while the technology allows for customization, many projects are still taking the path of least resistance,” said a Dune analyst. “But after KelpDAO, that calculus may change.”
With cross-chain TVL continuing to grow, the security of Layerzero and similar protocols remains a critical focus. Developers may need to adopt multi-verifier configurations to protect users and restore confidence in cross-chain infrastructure.

