Security is a setting
LayerZero does not impose one verification model: each application chooses its own configuration, and the default set is documented. That flexibility is why it reaches more chains than anything else, and it means the security of your transfer depends on a choice made by the app you are using, which you generally cannot see.
April 2026
Kelp DAO's adapter ran a single-point verification setup. An attacker sent a crafted message and minted 116,500 unbacked rsETH — roughly $292m, the largest DeFi loss of the year. The messaging protocol's own contracts were not exploited, and that is exactly the point worth making: a configurable design pushes the hardest decision onto integrators, and integrators get it wrong.
What it does well
Unified liquidity through Stargate gives predictable transfer pricing, delivery is fast, and fees are published per route. No protocol-level exploit appears on its record.
How to use it
Prefer applications that publish their verification configuration, and treat coverage of an obscure chain as a reason for caution rather than confidence — the long tail is where weak configurations live.
Who it suits
Users who need a route nothing else covers, and builders who will configure verification deliberately rather than accept whichever default ships. The flexibility is genuinely valuable to the second group and genuinely dangerous in the hands of the careless.