Wyoming Cites LayerZero Security Failures in Switch of State Stable Token to Chainlink CCIP

Wyoming’s Stable Token Commission on September 14 published its fullest account of why the state’s Frontier Stable Token left LayerZero and now uses Chainlink’s Cross-Chain Interoperability Protocol as its only approved path between blockchains.

The statement came from Keith Lawhorn, the Commission’s chief information security officer.

He said officials owe FRNT holders a duty of care because the token is the first dollar-backed digital asset issued by a US state and is treated as a public good.

That duty, he wrote, required a hard look at the messaging layer that moves FRNT across eight networks after a major LayerZero-related theft earlier this year.The review began after the April 18, 2026 attack on a LayerZero bridge used by KelpDAO.

According to LayerZero’s own incident report, as cited by Lawhorn, attackers affiliated with North Korea breached off-chain infrastructure operated by LayerZero Labs.

A verifier that watched Unichain then accepted a fabricated event. Funds were released on Ethereum even though the corresponding action on Unichain never happened.

The loss was about $292 million. Wyoming wanted to know whether similar weaknesses sat under FRNT.

Lawhorn said the answer was yes, and that the problems were operational as well as architectural.

He described a repeated pattern of failures at LayerZero Labs.

One recent access-control lapse, he wrote, involved the company’s failure to transfer a production authorization to the Commission.

While that issue was being fixed, the state learned that LayerZero also had not kept proper control of a critical private key used to manage a live FRNT production deployment.

Officials were further troubled by what they called inadequate disclosure of incidents, including events that never became public.

Those findings, Lawhorn argued, matter more for a government issuer than for a typical DeFi project.

The relevant test is not whether a bridge can be configured securely in theory.

It is whether the system is secure by default, independently auditable, resilient when something goes wrong, and transparent enough to protect a public program.

In the Commission’s judgment, LayerZero no longer met that test.

Too much security work is left to each developer.

Many deployments, he said, end up relying on a single verifier or a very small set because few independent verifiers are available.

In a public financial system, he wrote, that is not an acceptable baseline.He pointed to two episodes as evidence.

The KelpDAO theft showed how one forged message, after LayerZero’s own systems were compromised, could drain an entire bridge balance.

An October 2025 Amazon Web Services outage then took LayerZero’s Stargate bridge offline, which the Commission treated as a resilience failure.

Even strong code, Lawhorn said, cannot rescue an operator that is undisciplined about keys, access, containment, and disclosure.

The Commission compared LayerZero with CCIP and other vendors on six dimensions and concluded that CCIP was the only option that cleared its institutional bar.

Lawhorn said CCIP builds protections into the protocol instead of asking issuers to assemble them.

It runs on Chainlink’s decentralized oracle network, which he said stayed online through market crashes, congestion, and the same AWS outage.

It carries SOC 2 Type 2 certification from a Big Four firm and dozens of outside audits.

Every supported chain uses a baseline of sixteen independent node operators, with a two-stage process that first requires consensus and then a separate signing step.

Issuers can set rate limits by token, lane, and direction to cap how much value can move in a window.

Token contracts and pool logic also remain under the issuer’s control, so Wyoming can change policy or leave without rebuilding FRNT.

The Commission had already finished the migration and retired the LayerZero and Stargate route.

The September 14 memo is the state’s public case for that decision and, Lawhorn said, a template for other governments that want to move regulated assets across chains without lowering the security standard they apply to any other critical system.



Sponsored Links by DQ Promote

 

 

0 0 votes
Article Rating
Subscribe
Notify of
guest

This site uses Akismet to reduce spam. Learn how your comment data is processed.

0 Comments
Newest
Oldest Most Voted
 
0
Would love your thoughts, please comment.x
()
x
Send this to a friend