LayerZero describes itself as “a permissionless, open framework designed to securely move information between blockchains.” Its OFT standard debits on a source chain and credits on a destination chain to keep one unified global supply, and it is deployed to more than 180 mainnet chains according to LayerZero’s own metadata API.
That reach is what makes the security problem unusual. A protocol that lives on one chain has one virtual machine to get right. LayerZero has to be correct in Solidity, in Rust twice over, in DAML, and in the off-chain TypeScript that validates messages between them.
Onchain and offchain, in every runtime
LayerZero’s attack surface spans several runtimes and extends well beyond its contracts. Onchain, the work calls for expertise in DAML authorisation on Canton, cross-program invocation on Solana and Soroban contracts on Stellar. Offchain, it covers the TypeScript validator stack that routes every message and the desktop client in which signers approve transactions.
Guardian staffs each surface with dedicated specialists and runs the reviews concurrently, which is why the engagements below proceed as parallel tracks rather than a single sequence.
The engagements
Twenty engagements across 2026, running as three concurrent tracks: the Canton/DAML build-out, the EVM and Solana Console work, and OneSig across every chain it touches.
Jan 2026
Canton OFT
LayerZero OFT implementation in DAML on Canton
Moving onto Canton meant reimplementing the OFT standard in DAML, with a different authorisation model and far fewer auditors who can read it. The first review returned fifty-eight findings, including two Criticals and five Highs, the highest-severity result in the account.
- 2Critical
- 5High
- 15Medium
- 24Low
- 12Info
Read the report →
Jan 2026
Console: the enterprise control plane, in Solidity
36 Solidity contracts · Portal and Nexus OFTs · upgradeable extensions
Console is LayerZero’s control plane for multichain assets. Guardian reviewed the Portal and Nexus OFT contracts, the upgradeable extensions, the message codec and the OFT registry.
Sixty-eight findings, mostly informational. The two Mediums: a Nexus composeFrom that drops the original sender, and a missing overflow validation.
Read the report →
Mar 2026
Console update review
Restructured Console tree · devtools diffs
A re-review after the Console tree was restructured. Two informational findings and nothing else, the cleanest result in the account.
Mar – Apr 2026
Canton DAML: the full production surface
4,833 lines of DAML · OApp, governance, multisig, registry, executor
Where January covered the OFT, this covered everything else on Canton: send and receive paths, governance, the multisig, the registry and the executor. Seventy-one findings, including a High.
- 1High
- 14Medium
- 36Low
- 20Info
Mar – Apr 2026
The validator stack: 11,246 lines of TypeScript
11,246 lines of TypeScript · message library, endpoint, DVN, executor, treasury
The off-chain infrastructure that validates and routes LayerZero messages: the message library, endpoint, DVN and its multisig, price feed, executor and treasury. The largest scope in the account, and sixty-eight findings including a High.
- 1High
- 3Medium
- 29Low
- 35Info
Mar – Apr 2026
Virtual Endpoints: emulating the EVM
EVM emulation · EVM contracts in TypeScript
Two parts: how LayerZero emulates the EVM, and how it implements EVM contracts in TypeScript, both places where a subtle divergence would surface only in production. Guardian fuzzed the emulation exhaustively and reviewed the TypeScript against the contracts it replaces.
Apr 2026
Solana OApp
2,670 lines of Rust · OApp program, endpoint CPI, Anchor framework · four rounds
Four rounds over the Solana OApp program, its endpoint calls, type handling and access-control macros. Forty-eight findings, none above Medium.
- 0Critical
- 0High
- 1Medium
- 9Low
- 38Info
Read the report →
May 2026
Solana Console
1,483 lines of Rust · Solana OFT, extensions, transfer-hook allowlist
Console’s Solana side: the OFT program, its extensions, and the transfer-hook program behind the allowlist and blocklist. Sixteen findings, all informational.
- 0Critical
- 0High
- 0Medium
- 0Low
- 16Info
Read the report →
May 2026
OneSig on Stellar
742 lines of Rust on Soroban · dedicated fuzzing
OneSig, the multisig behind LayerZero’s privileged operations, on Soroban. Seven findings, four Lows and three Informational, in a report LayerZero publishes in its own audit index.
- 0Critical
- 0High
- 0Medium
- 4Low
- 3Info
Read it in LayerZero’s audit index →
Jun – Aug 2026
OneSig on Solana
980 lines of Rust · four remediation rounds
OneSig on Solana: merkle and signature validation, execution and configuration. Seventeen findings, all informational, then four remediation rounds through August.
- 0Critical
- 0High
- 0Medium
- 0Low
- 17Info
Jun – Aug 2026
Validator stack updates
Production DAML and the validator TypeScript · four remediation rounds
The follow-up to the March validator review, covering the production DAML alongside the TypeScript. Thirty-six findings on the main review, then four remediation rounds and a configuration pass through late August.
Read the report →
Jul 2026
OneSig on Canton
OneSig implemented in DAML on Canton · three remediation rounds
OneSig on its fifth runtime. Twenty-four findings, two Mediums, twenty-one Lows and an Informational, across three remediation rounds.
Jul 2026
The OneSig pentest
Electron desktop signer · React UI · per-chain encoders
Every OneSig contract review assumes the signer sees what they are approving. This engagement tested that by attacking the client application itself. Eighty-two findings, including seven Highs.
- 7High
- 47Medium
- 20Low
- 8Info
Jul 2026
Console EVM, next generation
Next-generation Console EVM tree · 3,013 source lines
The newest Console EVM tree: one Low and three Informational findings. The consolidated Console report, published in LayerZero’s audit index, covers three rounds and 80 findings. It states that “no High or Critical findings were identified across the original engagement or updates review.” Guardian gave it its top confidence ranking, 5 out of 5.
- 0Critical
- 0High
- 0Medium
- 1Low
- 3Info
Read it in LayerZero’s audit index →
Looking for a partnership like this?
We work closely with our partners to address their most critical security needs: every update reviewed as it ships, every deployment checked before it goes live, by a team that already knows the codebase. Tell us what you’re building and we’ll scope a long-term partnership around it.
Get a quote