Invest1 publisher3 min readPublished
Wyoming details pattern of LayerZero failures, including a mismanaged key, behind its exit to Chainlink's CCIP
The Stable Token Commission's September 14 memo opens with a $292 million North Korea-linked bridge theft and ends with two access-control lapses under Wyoming's own token, 149 days after the attack that started the review.
The Investor · Invest desk

What happened
- Wyoming's Stable Token Commission published its fullest account on September 14 of why the Frontier Stable Token left LayerZero and now uses Chainlink's CCIP as its only approved path between blockchains.
- The review began after the April 18, 2026 attack on a LayerZero bridge used by KelpDAO, in which a verifier accepted a fabricated Unichain event and about $292 million was released on Ethereum.
- The Commission scored LayerZero, CCIP and other vendors on six dimensions and concluded that CCIP alone cleared its institutional bar, citing sixteen independent node operators per chain and SOC 2 Type 2 certification.
Compiled by The InvestorSomething wrong?How this is made
Why it matters
- capability Setting rate limits by token, lane and direction moves the maximum loss from a forged message out of the vendor's design and into a policy number the Commission chooses.
- precedent Lawhorn offered the document as a template for governments moving regulated assets across chains, so the next public issuer keeping a bridge vendor after an off-chain compromise has a published standard to answer to.
- exposure LayerZero's disclosure practice is now on a state record, including incidents the Commission says reached it but never became public, which any regulated counterparty can raise in diligence.
The sequence matters more than the headline number. The KelpDAO bridge was attacked on April 18, 2026 [5], the Commission's account appeared 149 days later [24], and by then the migration was finished and the LayerZero and Stargate route retired [22]. Wyoming filed its justification after the position was closed.
Keith Lawhorn, the Commission's chief information security officer, framed the review as a duty of care owed to FRNT holders. That is because the token is the first dollar-backed digital asset issued by a US state and is treated as a public good [2][3]. The $292 million loss gave Wyoming its reason to look [8]. What he says the state found under its own token was two access-control lapses. LayerZero had not transferred a production authorization to the Commission. While that was being fixed, the state learned the company had not kept proper control of a private key used to manage a live FRNT production deployment [10][11]. He also wrote that incident disclosure was inadequate, including events that never became public [12]. LayerZero is not quoted in the account. The loss figure comes from LayerZero's own incident report as cited by Lawhorn [6][8].
The Commission's test was whether a system is secure by default, independently auditable, resilient when something goes wrong, and transparent enough to protect a public program. It concluded LayerZero no longer met that test [13]. CCIP's baseline is sixteen independent node operators on every supported chain, with consensus first and a separate signing step [19]. LayerZero deployments, Lawhorn said, often lean on one verifier or a very small set, because few independent verifiers exist [14]. Sixteen verifiers means sixteen parties have to be wrong at the same moment [25]. Wyoming has also made CCIP the only approved path for a token that moves across eight networks [1][4]. The term that keeps the choice reversible is ownership: token contracts and pool logic stay under the issuer's control, so the state can change policy or leave without rebuilding FRNT [21].
The counter-case is in Wyoming's own evidence. The KelpDAO failure was in off-chain infrastructure operated by LayerZero Labs, where a verifier watching Unichain accepted a fabricated event and funds were released on Ethereum [6][7]. A decentralized oracle network has off-chain operators of its own. SOC 2 Type 2 certification from a Big Four firm and dozens of outside audits describe process discipline [18]; staying online through the October 2025 AWS outage that took Stargate down describes uptime [15][17]. Rate limits by token, lane and direction cap how much value can move in a window [20].
For another public issuer, the usable part of the memo is the pair of access-control lapses. Key custody and authorization transfer are things a buyer can ask a vendor about before signing. Lawhorn offered the document as a template for governments moving regulated assets across chains without lowering their security standard [23]. The account does not identify the other vendors scored on the six dimensions, or the cost of the move [16][26]. The reasoning would look wrong if a compromised operator inside CCIP's set ever produced a message that cleared both the consensus and the signing stage [19].
What to watch
- Any response from LayerZero Labs to the Commission's account of the production key and the untransferred authorization.
- Whether another state or public issuer cites the September 14 memo in its own vendor selection record.
- Published per-lane rate limits for FRNT, which would show the maximum value the Commission is willing to expose in one window.