FORESHOCK

Only protocols with enough independently verified data to trust a score appear here. This is a permanent rule, not a temporary gap.

Coverage grows three ways: protocols Foreshock selects at its own discretion, protocols requested through the Request coverage button, and sponsored assessments delivered on an agreed timeline. No path has a guaranteed date except sponsorship.

LayerZero V2

Multi-Chain

low:

  • This methodology version hasn't been backtested against any historical incidents in this protocol's bucket yet.
  • This is not because this protocol's data is thin (70% of category weight is verified data).
Why this rating
Every category's contribution to the overall score, highest first.
Dependency risk12.0Verified

Uses 5 oracles (LayerZero V2's security model replaced v1's fixed Oracle+Relayer pair with Decentralized Verifier Networks (DVNs) - independent entities that verify cross-chain message hashes before the destination chain's Message Library accepts them. Each application (OApp) configures its own DVN set and threshold (an X-of-Y-of-N model); a commonly cited example configuration is 2-of-3-of-5 (two required DVNs plus any three of five optional DVNs must sign off), used here as the representative count since LayerZero the protocol has no single fixed DVN set of its own - this is a genuine structural difference from a protocol with one canonical oracle committee, disclosed rather than smoothed over. Risk stated plainly in LayerZero's own materials: if all required DVNs plus enough optional DVNs collude, they can forge a fake message.).

Audit profile10.0Verified

2 audits/contests on record, most recent (Zellic, 2023-12-01) has unread findings, scored as unknown, not assumed clean.

Code characteristics7.5Unverified

No verified evidence yet; held at the neutral midpoint rather than assumed safe or unsafe.

Governance attack surface5.0Unverified

No verified evidence yet; held at the neutral midpoint rather than assumed safe or unsafe.

TVL profile3.5Verified

TVL change (-4%) is within a stable range.

Team factors2.5Unverified

No verified evidence yet; held at the neutral midpoint rather than assumed safe or unsafe.

Historical incidents2.3Verified

No known own or inherited incidents.

Protocol age1.5Verified

917 days live, past the ~1yr floor; treated the same as any older protocol, not scored progressively safer with more age.

Bug bounty0.7Verified

Has a bug bounty program, up to $15 000 000, hosted on Immunefi.

Dependencies (1)

Uses 5 oracles (LayerZero V2's security model replaced v1's fixed Oracle+Relayer pair with Decentralized Verifier Networks (DVNs) - independent entities that verify cross-chain message hashes before the destination chain's Message Library accepts them. Each application (OApp) configures its own DVN set and threshold (an X-of-Y-of-N model); a commonly cited example configuration is 2-of-3-of-5 (two required DVNs plus any three of five optional DVNs must sign off), used here as the representative count since LayerZero the protocol has no single fixed DVN set of its own - this is a genuine structural difference from a protocol with one canonical oracle committee, disclosed rather than smoothed over. Risk stated plainly in LayerZero's own materials: if all required DVNs plus enough optional DVNs collude, they can forge a fake message.).

Incident history (0)

No material incidents on record.

Audit history (2)
  • Zellic 2023-12-01

    Findings not confirmed in this research pass.

  • Zellic 2023-08-01

    Findings not confirmed in this research pass.

This assessment follows Foreshock's published methodology. Exact category weights, scoring rules, thresholds, and aggregation logic are proprietary and not shown here. How to interpret this assessment

Do you hold a position in this protocol?

Get an email when this assessment materially changes.

LayerZero V2 · Foreshock