Wyoming: LayerZero Loses State Stablecoin, Chainlink Takes Over

By: journalducoin.com|2026/09/19 13:00:00

Trust, blockchain version. On September 14, the cybersecurity chief of the Wyoming Stable Token Commission published a lengthy indictment against LayerZero. He has just replaced this provider with Chainlink to facilitate the circulation of the state stablecoin FRNT across eight blockchains. Production authorization was never transferred, private key poorly controlled. These two flaws are enough to fuel the accusation, which is compounded by disclosures deemed insufficient regarding past incidents. A few hours later, the head of LayerZero responds, backing his claims with blockchain transaction addresses. The clash pits two irreconcilable versions of the same key transfer against each other. It concerns a stablecoin backed by U.S. Treasury bonds and already deployed on eight networks.

Key points of this article:

  • Wyoming has replaced LayerZero with Chainlink to secure its state stablecoin FRNT following accusations of security flaws.
  • LayerZero has countered by presenting blockchain evidence to contest the accusations but has already lost the trust of several major clients.

FRNT and the Forgotten Key, Wyoming's Indictment

Keith Lawhorn, the cybersecurity chief of the Commission, details his investigation in a thread posted on X. He posts it at 2:57 PM Paris time. The starting point dates back to April. The exploit of $292 million emptied KelpDAO's coffers after a compromise of LayerZero Labs' RPC infrastructure. This hack is believed to be the work of North Korean hackers. The shockwave prompted Wyoming to audit its own reliance on LayerZero for the FRNT. This stablecoin is the first issued by a U.S. state, deployed on eight networks (Arbitrum, Avalanche, Base, Ethereum, Hedera, Optimism, Polygon, and Solana). It is also backed by U.S. Treasury bonds at a rate of 102% over-collateralization.

The audit did not go well for LayerZero. Worse, while digging into this access issue, the Wyoming team claims to have discovered that a critical private key remained under LayerZero's control. LayerZero was using it to manage a real FRNT deployment, even though it should have been under the Commission's purview. To this, add disclosures deemed too scant regarding past incidents, both public and private. The Commission says it had no choice but to sever ties to protect token holders.

LayerZero Presents On-Chain Evidence

Seven hours later, at 7:50 PM, the co-founder and CEO of LayerZero responds in a separate thread. He presents it as a clarification against what he considers exaggerated publications. His version: LayerZero deployed FRNT on Solana at Wyoming's request, with all extensions activated. Only one, the authority << Scaled UI Amount >>, was not transferred in the process. According to him, this is an omission on both sides.

On the technical substance, the difference matters. This extension, the Scaled UI Amount, is only used to display a scaling factor of amounts in the interface. It does not allow for minting, burning, or freezing tokens. In fact, it has never moved from its default value during the entire period in question. As soon as the oversight was reported, the transfer to Wyoming's wallet took less than 24 hours. LayerZero published the on-chain addresses to support this. Pellegrino describes the accusation of a << lost >> key as inaccurate and even quite surprising. The transfer transaction remains accessible to anyone on the Solana blockchain.

LayerZero Loses Ground Against Kelp, Kraken, and Wyoming

Wyoming is not an isolated case. Kraken and the restaking platform Lombard abandoned LayerZero in favor of Chainlink CCIP as early as May, just weeks after the KelpDAO exploit. This was to secure the wrapped bitcoin kBTC and future wrapped assets from the exchange. Together, these departures have migrated over four billion dollars in value to the Chainlink infrastructure.

The KelpDAO exploit remains the centerpiece of this issue. According to CoinDesk's investigation, attackers affiliated with North Korea compromised the RPC infrastructure exploited by LayerZero Labs. This allowed them to forge an inter-chain message releasing funds on Ethereum. This event never actually took place on Unichain. LayerZero has since acknowledged its share of responsibility in the incident. However, for regulated issuers, a protocol that allowed such manipulation is concerning. This weighs more heavily than a mere isolated bug.

-- Price

--
--
--

Chainlink CCIP and the SOC 2 Certification Arrived Six Days Too Late

In his thread, Lawhorn also justifies the choice of Chainlink CCIP with a list of technical criteria. Sixteen independent node operators must validate each message before its signature. Throughputs are regulated by token, path, and direction, to cap the value that can move within a given window. The CCT standard finally guarantees issuers ownership of their contracts without relying on the code of a single provider. Additionally, there is a SOC 2 Type 2 certification. According to Lawhorn, LayerZero did not offer this at the time of the security review. The problem is that this list almost verbatim repeats the arguments that Chainlink promotes on its own account. This detail does not detract from their accuracy but invites verification rather than mere replication.

The Wyoming Audit Was Also Outdated

And the verification holds a surprise. LayerZero Labs announced on September 8 that it had obtained SOC 2 Type 1 and Type 2 accreditation for its entire infrastructure. This is six days before Lawhorn's thread was published. The compliance gap that the Commission brandished as a decisive argument had already closed by the time it was made public. The Wyoming security review, however, dates back to before the end of August. The argument held water at the time of the audit, but not at the time of publication.

This discrepancy does not change the vulnerabilities revealed by the KelpDAO exploit nor the legitimacy of Wyoming's operational choice. A snapshot of crypto security quickly becomes outdated. A regulator relying on the marketing arguments of a provider, even if it is the new one, would benefit from rechecking its own files before publishing them. This is exactly the same requirement that Wyoming now imposes on LayerZero, applied this time to itself. Another state preparing to launch its own stablecoin will have to deal with this type of race. The same goes for a bank preparing an inter-chain bridge for its tokenized assets. Crypto security certifications are never guaranteed: they must be rechecked with every announcement.

This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.

You may also like

iconiconiconiconiconiconicon
Customer Support:@weikecs
Business Cooperation:@weikecs
Quant Trading & MM:bd@weex.com
VIP Program:support@weex.com