The Wyoming Stable Token Commission on September 14 published a detailed security memo explaining why the State of Wyoming removed LayerZero as cross-chain infrastructure for its Frontier Stable Token (FRNT) and replaced it with Chainlink's Cross-Chain Interoperability Protocol (CCIP). The memo, ...
"The Commission proactively conducted a security review and identified concerns regarding LayerZero's disclosure practices and operational security. Following the review, the Commission decided to adopt Chainlink CCIP as it is the only cross-chain infrastructure that met our stringent security and reliability requirements across the board." — Anthony Apollo, Executive Director, Wyoming Stable Token Commission
The Wyoming Stable Token Commission on September 14 published a detailed security memo explaining why the State of Wyoming removed LayerZero as cross-chain infrastructure for its Frontier Stable Token (FRNT) and replaced it with Chainlink's Cross-Chain Interoperability Protocol (CCIP). The memo, authored by Commission CISO Keith Lawhorn, cited "a repeated pattern of major operational security failures at LayerZero Labs," including loss of control over a critical private key, insufficient independent verifier options, and a security model that "places too much responsibility on individual developers to assemble their own security."
Wyoming is the first U.S. state to issue a dollar-backed stablecoin. FRNT launched in January 2026, is deployed across eight blockchains, and is backed by U.S. Treasuries managed by Franklin Templeton. The decision to replace cross-chain infrastructure on security grounds — and to publish the rationale publicly — is without precedent among U.S. government entities operating on public blockchains.
The move is part of a broader migration pattern: roughly $15 billion in on-chain value has shifted from LayerZero to competitors since April 2026, when the $292 million KelpDAO bridge exploit exposed structural weaknesses in LayerZero's verifier architecture.
On April 18, 2026, attackers drained 116,500 rsETH (approximately $292 million) from a LayerZero-powered bridge operated by KelpDAO. The attack was not a smart contract vulnerability. Mandiant, CrowdStrike, and Chainalysis attributed it to DPRK threat actor TraderTraitor (also tracked as UNC4899), a unit within North Korea's Lazarus Group.
The breach timeline, according to LayerZero's own incident report:
The structural issue: KelpDAO had configured its bridge with a 1-of-1 DVN setup — a single verifier controlled entirely by LayerZero Labs. At the time of the exploit, 47% of all active LayerZero OApp contracts used the same 1-of-1 DVN configuration. Two follow-up attempts at 18:26 and 18:28 UTC, targeting an additional 40,000 rsETH (~$100 million), were blocked by Kelp's emergency multisig, which paused core contracts 46 minutes after the initial drain.
The exploit triggered withdrawals that pulled more than $10 billion from lending protocol Aave and created a significant bad-debt position on the platform. It was the largest DeFi exploit of 2026.
Wyoming's review began shortly after the KelpDAO exploit. CISO Keith Lawhorn evaluated LayerZero, Chainlink CCIP, and other unnamed cross-chain providers across six categories. The September 14 memo laid out the Commission's findings.
Findings against LayerZero:
Why CCIP was selected:
Lawhorn described the memo as "a template for other governments that want to move regulated assets across chains without lowering the security standard they apply to any other critical system."
Wyoming's decision is consistent with a broader pattern. Since the April 2026 KelpDAO exploit, approximately $15 billion in on-chain value has shifted from LayerZero-based infrastructure to alternatives, according to industry data compiled by Cryptonomist. Major migrations include:
| Protocol | Value Migrated | Asset Type | Destination | |---|---|---|---| | KelpDAO | ~$292M (remaining assets) | rsETH restaking token | Chainlink CCIP | | Solv Protocol | $700M+ | SolvBTC, xSolvBTC tokenized BTC | Chainlink CCIP | | Lombard | Undisclosed (large) | Tokenized BTC | Chainlink CCIP | | Re Protocol | $475M+ TVL | reUSD stablecoin | Chainlink CCIP | | Kraken | Exchange-wide | Cross-chain standard | Chainlink CCIP | | Wyoming (FRNT) | <$1M supply | State-issued stablecoin | Chainlink CCIP |
LayerZero entered 2026 handling an estimated 57% of all cross-chain messaging volume, processing approximately $293 million daily across 132+ supported blockchains. Post-exploit, bridge volume through LayerZero dropped to a reported low of $91 million. Chainlink CCIP absorbed over $1.1 billion in token value in a single week during the May migration wave.
Several major token issuers continue to use LayerZero's OFT infrastructure: Ethena (USDe/sUSDe), Etherfi (weETH), Tether (USDT0), and BitGo (WBTC).
LayerZero Labs took several steps following the exploit:
Pellegrino disputed Lawhorn's characterization of the key-management incident, calling it a minor view-only metadata issue that was resolved quickly.
Wyoming has now consolidated cross-chain messaging, bridging, and reserve verification under a single infrastructure provider: Chainlink. The Commission also adopted Chainlink Proof of Reserve on September 2, 2026, pushing bank and Treasury reserve figures into public smart contracts in near real time. It is also implementing Chainlink Proof of Reserve Secure Mint, which requires verified reserves to equal or exceed FRNT's total supply before new tokens can be minted.
This consolidation simplifies audits and reduces integration surface area. It also creates a single-vendor dependency. If Chainlink's oracle network experienced a sustained failure, FRNT's cross-chain movement, reserve verification, and minting controls would all be affected simultaneously.
FRNT's current supply sits under $1 million, which limits the practical risk at present. The transparency infrastructure currently outweighs the token itself in scope and ambition. Whether that balance holds as FRNT scales — if it does — will test the single-provider model.
The Network Firm continues to examine FRNT reserve and token-supply balances under AICPA standards, providing an off-chain verification layer independent of Chainlink.
The interoperability market was valued at $619 million in 2024, with projections reaching $2.56 billion by 2030 at a 26.6% CAGR, according to BlockEden research. Each major protocol takes a structurally different approach to the verification problem:
Chainlink CCIP: Fixed set of 16+ independent, security-reviewed node operators per chain. Two-stage verification (OCR consensus + signing). SOC 2 Type 2 certified. Secures approximately $7 billion in Coinbase wrapped tokens. No validator-layer exploit to date.
LayerZero: Modular model — applications choose their own DVN sets. Supports 132+ chains with the broadest coverage. Handles 75% of cross-chain volume ($293M daily pre-exploit). Immutable endpoints. Post-KelpDAO default raised to 3-of-3 DVN minimum.
Wormhole: Fixed committee of 19 institutional Guardian validators (including Google Cloud). Requires 13-of-19 signatures. Processed $65B+ lifetime volume. Experienced a $326 million exploit in 2022, after which it deployed Global Accountant, Governor rate-limiting, and a $10 million bug bounty. The only protocol unconditionally approved by Uniswap's Bridge Assessment Committee.
The fundamental trade-off: fixed-committee models (CCIP, Wormhole) offer predictable security but concentrate trust in known operator sets. Modular models (LayerZero) distribute configuration authority but shift security responsibility to developers, creating heterogeneous risk profiles across the ecosystem.
Wyoming's September 14 memo is a 12-page document about a sub-$1 million stablecoin, but its implications extend well beyond FRNT's current scale. It is the first publicly documented case of a U.S. government entity evaluating cross-chain infrastructure against institutional security standards, finding it deficient, and publishing the criteria that guided its replacement.
The broader market has moved in the same direction. Approximately $15 billion in on-chain value has migrated away from LayerZero since the KelpDAO exploit, with Chainlink CCIP absorbing the majority. LayerZero retains significant market presence — processing 75% of cross-chain volume pre-exploit and continuing to serve major issuers including Tether and Ethena — but its security model now faces structural scrutiny from institutional adopters.
The interoperability market is splitting along institutional lines. Protocols and governments managing regulated or high-value assets are gravitating toward fixed-committee verification models with third-party compliance attestation. Protocols prioritizing speed, chain coverage, and developer flexibility continue to find utility in modular approaches.
Wyoming's contribution is procedural, not technological: a public, auditable framework for evaluating cross-chain security that other government entities can adopt, modify, or reject on the merits. Whether other states or federal agencies follow that template will depend less on FRNT's success and more on whether any of them decide to put regulated assets on public blockchains in the first place.