What is LayerZero?
LayerZero is a protocol that lets smart contracts on one blockchain send verified messages to another, which is how many tokens, including major stablecoins, move across chains. ZRO is its governance token, and LayerZero entities use revenue from the Stargate bridge to buy it back.
Utility Lens
What LayerZero actually does
Lets apps and token issuers send messages and move assets between many blockchains without building a separate bridge for each pair.
- Real-world usage
- establishedLayerZero carries large, sustained cross-chain volume for major tokens and stablecoins across dozens of networks.
- Token necessity
- optionalMessages are paid for in each chain's native gas token and the fee switch has never been turned on, so the protocol works without ZRO.
- Decentralization
- limitedApps can pick their own verifiers, but many rely on LayerZero Labs' default verifier and executor, a weakness exposed in the April 2026 KelpDAO exploit.
- Track record
- provenLive since 2022, but April 2026 brought a $292 million exploit of an app that used a single LayerZero Labs verifier.
What it’s used for
Token issuers use LayerZero's Omnichain Fungible Token standard so one token can exist on many chains, and users bridge assets through apps like Stargate, often without realizing LayerZero is underneath. ZRO holders vote in twice-yearly referendums on whether to switch on a protocol fee, which would be converted to ZRO and burned.
Role of the ZRO token:
Evidence of real use
- LayerZero says it has moved over $260 billion in value across 165 networks and carries about 70% of cross-chain stablecoin flow (company figures). Source
- All four fee switch referendums, held from December 2024 to June 2026, ended with the fee switch off. Source
- On April 18, 2026, attackers forged a LayerZero message to drain about $292 million of rsETH from KelpDAO's bridge, which relied on a single verifier; no smart contract bug was involved. Source
How LayerZero works
LayerZero places a small, non-upgradable contract called an endpoint on each connected chain. When an app wants to send a message, for example 'release 100 tokens on chain B', it calls the endpoint on chain A. The message is then checked by one or more Decentralized Verifier Networks (DVNs) that the app has chosen, and once enough verifiers sign off, an executor delivers it to the destination contract. Fees are paid in the source chain's native gas token.
The key design choice is that each application sets its own security. An app can require several independent DVNs to agree, which is safer, or rely on just one, which is cheaper but creates a single point of failure. In April 2026, attackers poisoned the data sources behind LayerZero Labs' verifier and forged a message to KelpDAO's single-verifier bridge, draining about $292 million of rsETH. LayerZero said it would stop attesting messages for apps using one-verifier setups.
ZRO launched in June 2024. Holders vote every six months on a fee switch that would add a protocol fee to each message and burn the proceeds in ZRO; so far every vote has kept it off. After acquiring the Stargate bridge in 2025, LayerZero directs Stargate's revenue to buying back ZRO, and it has announced Zero, a separate layer-1 blockchain aimed at capital markets.
Key moments
- 2022LayerZero launches on mainnet in March alongside the Stargate bridge.
- 2024LayerZero V2 goes live in January; ZRO launches in June with an airdrop that asked claimants to donate $0.10 per token to Protocol Guild.
- 2025LayerZero acquires Stargate and begins ZRO buybacks, including 50 million ZRO repurchased from strategic partners in September.
- 2026Zero, a new LayerZero blockchain, is announced in February; in April a single-verifier setup is exploited in the KelpDAO rsETH hack.
Supply
ZRO has a fixed total supply of 1 billion tokens. As of LayerZero's 2026 update, about 514 million were unlocked and the rest vests to the foundation, strategic partners and core contributors. LayerZero entities buy back ZRO with Stargate revenue and treasury funds, and a protocol fee, if ever approved, would burn ZRO.
Risks to understand
- Security depends on how each app configures its verifiers, and the April 2026 KelpDAO exploit showed single-verifier setups can fail badly.
- ZRO's link to protocol usage relies on buybacks and a fee switch that holders have repeatedly voted against.
- Hundreds of millions of ZRO are still vesting, which adds future supply.
- Cross-chain messaging is a frequent target for state-backed hackers, and bridge failures can spread losses across DeFi.
LayerZero FAQ
Do I need ZRO to use LayerZero?
No. Cross-chain messages are paid for in each chain's native gas token, and ZRO is mainly used for governance.
Was LayerZero hacked in 2026?
In April 2026, attackers compromised data sources used by LayerZero Labs' verifier and forged a message to KelpDAO's bridge, which relied on that single verifier. About $292 million of rsETH was drained, though no smart contract bug was found.
What is the fee switch?
It is a proposed protocol fee on each LayerZero message, converted to ZRO and burned. ZRO holders vote on it every six months, and it has stayed off each time.
Sources
- The ZRO Token — LayerZero
- LayerZero Fee Switch Referendum — LayerZero Foundation
- $292 Million Lost, Zero Bugs Found: Lessons From the rsETH Bridge Exploit — OpenZeppelin
- KelpDAO/LayerZero Exploit Drains $290m, Freezes DeFi Markets — Galaxy Research
- Understanding LayerZero: A Comprehensive Overview — Messari
- LayerZero Airdrop Is Creating Chaos for Polymarket Bettors — Decrypt
- Ecosystem Update - 9/15/26 — LayerZero
Last reviewed October 4, 2026 by The Crypto Guide editorial team. Utility Lens ratings are editorial judgments, not investment advice. Market data from CoinGecko. Spot an error? Request a correction.
