Wyoming: LayerZero Loses State Stablecoin, Chainlink Takes Over
Trust, blockchain version. On September 14, the cybersecurity chief of the Wyoming Stable Token Commission published a lengthy indictment against LayerZero. He has just replaced this provider with Chainlink to facilitate the circulation of the state stablecoin FRNT across eight blockchains. Production authorization was never transferred, private key poorly controlled. These two flaws are enough to fuel the accusation, which is compounded by disclosures deemed insufficient regarding past incidents. A few hours later, the head of LayerZero responds, backing his claims with blockchain transaction addresses. The clash pits two irreconcilable versions of the same key transfer against each other. It concerns a stablecoin backed by U.S. Treasury bonds and already deployed on eight networks.
Key points of this article:
- Wyoming has replaced LayerZero with Chainlink to secure its state stablecoin FRNT following accusations of security flaws.
- LayerZero has countered by presenting blockchain evidence to contest the accusations but has already lost the trust of several major clients.
FRNT and the Forgotten Key, Wyoming's Indictment
Keith Lawhorn, the cybersecurity chief of the Commission, details his investigation in a thread posted on X. He posts it at 2:57 PM Paris time. The starting point dates back to April. The exploit of $292 million emptied KelpDAO's coffers after a compromise of LayerZero Labs' RPC infrastructure. This hack is believed to be the work of North Korean hackers. The shockwave prompted Wyoming to audit its own reliance on LayerZero for the FRNT. This stablecoin is the first issued by a U.S. state, deployed on eight networks (Arbitrum, Avalanche, Base, Ethereum, Hedera, Optimism, Polygon, and Solana). It is also backed by U.S. Treasury bonds at a rate of 102% over-collateralization.
The audit did not go well for LayerZero. Worse, while digging into this access issue, the Wyoming team claims to have discovered that a critical private key remained under LayerZero's control. LayerZero was using it to manage a real FRNT deployment, even though it should have been under the Commission's purview. To this, add disclosures deemed too scant regarding past incidents, both public and private. The Commission says it had no choice but to sever ties to protect token holders.
LayerZero Presents On-Chain Evidence
Seven hours later, at 7:50 PM, the co-founder and CEO of LayerZero responds in a separate thread. He presents it as a clarification against what he considers exaggerated publications. His version: LayerZero deployed FRNT on Solana at Wyoming's request, with all extensions activated. Only one, the authority << Scaled UI Amount >>, was not transferred in the process. According to him, this is an omission on both sides.
On the technical substance, the difference matters. This extension, the Scaled UI Amount, is only used to display a scaling factor of amounts in the interface. It does not allow for minting, burning, or freezing tokens. In fact, it has never moved from its default value during the entire period in question. As soon as the oversight was reported, the transfer to Wyoming's wallet took less than 24 hours. LayerZero published the on-chain addresses to support this. Pellegrino describes the accusation of a << lost >> key as inaccurate and even quite surprising. The transfer transaction remains accessible to anyone on the Solana blockchain.
LayerZero Loses Ground Against Kelp, Kraken, and Wyoming
Wyoming is not an isolated case. Kraken and the restaking platform Lombard abandoned LayerZero in favor of Chainlink CCIP as early as May, just weeks after the KelpDAO exploit. This was to secure the wrapped bitcoin kBTC and future wrapped assets from the exchange. Together, these departures have migrated over four billion dollars in value to the Chainlink infrastructure.
The KelpDAO exploit remains the centerpiece of this issue. According to CoinDesk's investigation, attackers affiliated with North Korea compromised the RPC infrastructure exploited by LayerZero Labs. This allowed them to forge an inter-chain message releasing funds on Ethereum. This event never actually took place on Unichain. LayerZero has since acknowledged its share of responsibility in the incident. However, for regulated issuers, a protocol that allowed such manipulation is concerning. This weighs more heavily than a mere isolated bug.
-- Price
Chainlink CCIP and the SOC 2 Certification Arrived Six Days Too Late
In his thread, Lawhorn also justifies the choice of Chainlink CCIP with a list of technical criteria. Sixteen independent node operators must validate each message before its signature. Throughputs are regulated by token, path, and direction, to cap the value that can move within a given window. The CCT standard finally guarantees issuers ownership of their contracts without relying on the code of a single provider. Additionally, there is a SOC 2 Type 2 certification. According to Lawhorn, LayerZero did not offer this at the time of the security review. The problem is that this list almost verbatim repeats the arguments that Chainlink promotes on its own account. This detail does not detract from their accuracy but invites verification rather than mere replication.
The Wyoming Audit Was Also Outdated
And the verification holds a surprise. LayerZero Labs announced on September 8 that it had obtained SOC 2 Type 1 and Type 2 accreditation for its entire infrastructure. This is six days before Lawhorn's thread was published. The compliance gap that the Commission brandished as a decisive argument had already closed by the time it was made public. The Wyoming security review, however, dates back to before the end of August. The argument held water at the time of the audit, but not at the time of publication.
This discrepancy does not change the vulnerabilities revealed by the KelpDAO exploit nor the legitimacy of Wyoming's operational choice. A snapshot of crypto security quickly becomes outdated. A regulator relying on the marketing arguments of a provider, even if it is the new one, would benefit from rechecking its own files before publishing them. This is exactly the same requirement that Wyoming now imposes on LayerZero, applied this time to itself. Another state preparing to launch its own stablecoin will have to deal with this type of race. The same goes for a bank preparing an inter-chain bridge for its tokenized assets. Crypto security certifications are never guaranteed: they must be rechecked with every announcement.
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
You may also like

Franklin Templeton, Janus Henderson: Wall Street Integrates into Crypto as Validator

Kyobo Life, SBI complete Korea-Japan stablecoin test

Did LayerZero lose the private key that allows the creation of stablecoins for the State of Wyoming?

Allbridge Processes $1.64 Billion in Tron

Jolt: Processing 10 Million Cycles Per Second, Alpha Stage

LayerZero Launches Quantum-Resistant Polynomial Commitment Scheme Akita, Deployed to Jolt zkVM

Hemi Genesis Drop Suffers Reentrancy Attack Resulting in Loss of Approximately 124.5 Million Tokens

LayerZero Supports Multi-Chain for KRW1 Stablecoin

Chainlink whale sends $7.6m in LINK to Coinbase

ARK Invest Predicts LayerZero Interoperability Business Will Reach Nine-Digit Annual Revenue

Stargate V1 Liquidity Pool to End on December 15, 2026

Wyoming Adds Chainlink's Reserve Verification Feature to State-Issued Stablecoin

LayerZero Introduces MEV-Resistant Batch AMM Mechanism OTTER

USD 1.527 million in tokens will be unlocked in 30 days

Wyoming Adopts Chainlink for FRNT On-Chain Reserve Verification

50 Hacking Incidents in the Crypto Industry in August Resulting in Losses of Approximately $136 Million

The Sandbox to Repay 1:1 SAND After Exploit

Web3 Opens New Battlefield in Traditional Finance

LayerZero Unveils Exchange Infrastructure Atlas

Chainlink unlocks DeFi lending for Coinbase tokenized stocks

LayerZero Aims to Become the Invisible Exchange of Finance, ZRO Surges by 30%

LayerZero Unveils ATLAS Exchange Engine

USDG0 Expands Multi-Chain Distribution Based on LayerZero

BitGo Changes $7.3 Billion WBTC Cross-Chain Service Provider to Chainlink CCIP

Circle's Public Blockchain Arc Appears to Be Live, Not Publicly Tested

Aave faced a withdrawal surge of $8.45 billion during the rsETH crisis, reigniting debates about the risk management capabilities of DeFi

North Korea’s $500M DeFi Heist Unveils New Cyber Warfare Tactics
Key Takeaways: North Korean operatives have obtained over $500 million from DeFi platforms in under three weeks. The…

DeFi Losses Top $600 Million Amid Kelp DAO Exploit and TVL Decline
Key Takeaways: Total DeFi losses have skyrocketed to approximately $1 billion recently, with $600M+ linked directly to the…

Kelp DAO Exploit Fallout Deepens as Attacker Routes $175M in ETH via Privacy Rails
Key Takeaways: The attacker moved $175 million in stolen ETH to new wallets using privacy tools. The exploit…







