LayerZero's Default Library Contract Poses $3B Risk; Multisig Signers Participated in Meme Token Trades

ZRO0.65%
PEPE-1.38%
According to PANews, LayerZero Labs' default library contract upgrade mechanism poses risks to over $3 billion in LZ OFT on May 8, with $178 million currently exposed to projects still using the default configuration. Security researcher Banteg flagged that the contract lacks time restrictions, allowing LayerZero Labs to immediately upgrade it and forge messages, similar to the rsETH hack. On-chain data revealed that LayerZero Labs' multisig signers participated in meme token trades, DEX swaps, and cross-chain bridge transactions, indicating production environment private keys were connected to external websites, increasing phishing risks. CEO Bryan Pellegrino confirmed the transactions were conducted by multisig team members, describing them as testing PEPE on the LZ OFT token standard rather than meme coin trading, and stated the involved members have been removed.
Disclaimer: The information on this page may come from third-party sources and is for reference only. It does not represent the views or opinions of Gate and does not constitute any financial, investment, or legal advice. Virtual asset trading involves high risk. Please do not rely solely on the information on this page when making decisions. For details, see the Disclaimer.
Comment
0/400
No comments