OAK — OnChain Attack Knowledge

Worked example · 2026-07

LayerZero Executor — hot wallets for the message-execution role drain simultaneously across eight chains, the signature of co-located key material — LayerZero (cross-chain) — 2026-07-15

Loss
~$2.4M reported across eight chains — BNB Chain, Base, Arbitrum, Avalanche, Optimism, Mantle, Plasma, and Ethereum. On-chain analyst Specter put the figure nearer ~$2.1M; LayerZero's team was reported as suspecting a ~$2.1M hack. Proceeds were bridged to Ethereum and consolidated into 956 ETH (~$1.8M) plus ~$322,000 USDC. OAK records $2.1M–$2.4M as a reported range; no operator accounting has been published.
OAK Techniques observed
OAK-T11.011 (Multi-chain Key-store Co-location — primary, inferred from the extraction signature rather than from disclosure. LayerZero Executors are the role that delivers and executes cross-chain messages on destination chains, funding that work from hot wallets on every chain they serve. Those wallets drained simultaneously across eight chains, which is precisely the diagnostic T11.011 names: an attacker does not compromise eight independent per-chain key stores at once, so near-simultaneous multi-chain outflow from a single operator role indicates the signing material for all eight shared one infrastructure layer. See techniques/T11.011-multi-chain-key-store-co-location.md). The consolidation to Ethereum and swap to ETH is OAK-T7.003.
Attribution
unattributed. No named individual or group, and no entry vector. PeckShield reported the breach and multiple independent on-chain analysts corroborated the movement of funds across their original chains to Ethereum. No attacker addresses have been published in the sources OAK has reviewed, and nothing links the operator to a tracked OAK actor.
Key teaching point
"Multi-chain" is frequently a product feature layered over a single-chain security model, and the blast radius of any compromise is set by that architecture, not by the chain count. The Executor role has to hold spendable balances on every chain it serves — that is inherent to what it does, and the funds at risk are operational gas floats rather than user deposits, which is why $2.4M rather than $240M. What the incident exposes is the shape of the exposure: eight chains fell together, which means there were never eight security boundaries, only one wearing eight hats. The load-bearing control is per-chain key isolation, so that compromising the Ethereum Executor's signing capability yields the Ethereum Executor's float and nothing else. The compensating controls are the ones that bound a hot-wallet role generally: keep only a working float on-chain with the remainder in cold reserve, cap per-window outflow per chain, and alert on any Executor spend that is not a message-execution gas payment. This is the same architectural finding OAK has recorded against exchange custody (Poloniex, HTX, Indodax, Phemex) — the novelty here is that it lands on cross-chain messaging infrastructure, where an operator role is by definition present on many chains at once and the temptation to run one key store for all of them is structural.

How the wallets were compromised is not publicly known. No entry vector has been disclosed — not by LayerZero, not by PeckShield, not by the independent analysts who corroborated the flow. OAK therefore asserts no entry-vector technique: whether this began as an endpoint compromise (T15.003), a credential compromise (T15.004), a vendor-pipeline compromise (T15.002), or something else is unestablished. The T11.011 mapping describes the architecture the extraction pattern reveals, which is an inference the technique explicitly supports; it is not a claim about how the attacker got in.

Summary

LayerZero is a cross-chain messaging protocol. Its Executor role is responsible for delivering and executing messages on destination chains — an operational function that requires spendable balances on every supported chain to pay execution gas.

On 2026-07-15, on-chain analyst Specter reported that LayerZero's Core Executor wallets had been compromised, with assets drained across BNB Chain, Base, Arbitrum, Avalanche, Optimism, Mantle, Plasma, and Ethereum. Security firm PeckShield reported the breach independently, and multiple analysts corroborated the flow as the stolen assets moved off their original chains. Reported totals range from ~$2.1M to ~$2.4M. The proceeds were bridged to Ethereum and consolidated into 956 ETH (~$1.8M) and about $322,000 in USDC.

No entry vector has been disclosed. Public reporting establishes that the Executor wallets were compromised and that funds moved, and stops there. LayerZero was reported as suspecting a ~$2.1M hack; OAK has not identified a published LayerZero statement giving a root cause, a final accounting, or remediation detail, and the protocol's core messaging contracts are not reported as implicated — this is a compromise of the wallets belonging to an operator role, not of the messaging protocol itself.

What the public record does establish unambiguously is the shape: eight chains, one role, drained together.

Timeline (UTC)

When Event OAK ref
(standing) Executor role holds spendable gas balances on every supported chain to deliver and execute cross-chain messages (standing T11.011 surface)
(unknown) Executor wallets compromised — entry vector not disclosed (unestablished)
2026-07-15 Assets drained near-simultaneously across BNB Chain, Base, Arbitrum, Avalanche, Optimism, Mantle, Plasma, and Ethereum; ~$2.1M–$2.4M T11.011
2026-07-15 Analyst Specter reports the Executor-wallet compromise; PeckShield reports the breach; independent analysts corroborate the cross-chain flow (detection, third-party)
2026-07-15 onward Proceeds bridged to Ethereum, consolidated into 956 ETH (~$1.8M) and ~$322K USDC T7.003
as of 2026-07-17 No published root cause, final accounting, or remediation detail identified by OAK (open)

What defenders observed

  • At-event (simultaneous multi-chain outflow is itself the architectural finding). Eight chains draining together from one operator role is not eight compromises; it is one compromise with an eight-chain blast radius. This pattern is the T11.011 diagnostic and it is readable from public chain data alone, without any disclosure from the operator — which is the only reason this incident is classifiable at all. Per-chain key isolation is what converts a single infrastructure compromise into a single-chain loss (M37).
  • Pre-event (an operator role that must hold value on every chain is a standing exposure). The Executor cannot do its job without spendable balances everywhere it operates, so the exposure cannot be designed away — only bounded. Keeping a working float on-chain with the remainder in cold reserve, and capping per-chain outflow per time window, are the controls that decide whether this class of compromise costs a gas float or a treasury (M19, M38).
  • Detection (third parties, not the operator). The compromise surfaced through an independent analyst and PeckShield. An operator role with predictable spending behaviour — Executors pay execution gas, in bounded amounts, tied to message delivery — is unusually easy to monitor: any Executor spend that does not correspond to a message execution is anomalous by construction. That the alert came from outside suggests no such invariant was being watched (M39).
  • Open (no vector, no accounting, no remediation). Two days on, the public record contains the fact of the compromise and the movement of funds, and nothing about cause. This bounds what OAK can honestly say and is the reason no entry-vector technique is mapped.

Public references

Discussion

This is a thin entry, preserved for its architectural signal rather than its forensics. There is no post-mortem, no entry vector, no attacker addresses, and a loss figure that only resolves to a range. Under OAK's cite-or-omit rule most of an incident write-up would normally be unwriteable on this evidence — and most of it is. What survives is the one thing public chain data establishes without any cooperation from the operator: eight chains, one role, drained together. T11.011 exists precisely to name that inference, because the extraction pattern is the evidence of the architecture, and it is the reason the entry is worth keeping despite everything it cannot say.

The reason it earns a place next to the exchange-custody anchors (Poloniex 2023, HTX 2023, Indodax 2024, Phemex 2025) is that it moves the co-location finding into a different kind of operator. Those were custodians holding customer assets, where per-chain key isolation is an obvious ask that was simply not met. An Executor is infrastructure: its multi-chain presence is not a product decision but the definition of the role, since delivering messages to eight chains means being able to pay gas on eight chains. That makes co-location more tempting and the exposure more structural — and it makes the bounding controls (working float on-chain, cold reserve behind it, per-chain outflow caps, an invariant that Executor spends must correspond to message executions) more important than the isolation control alone, because some value must live on every chain no matter how well the keys are separated.

It is worth being precise about what did not happen, since LayerZero's name attaches to several distinct incidents in OAK's corpus. The messaging protocol was not exploited. This is not a peer-redirect issue like examples/2026-05-stake-dao-vsdcrv-layerzero-oft-peer-redirect.md, nor a bridge-integration compromise like examples/2026-04-kelpdai-rseth-bridge-layerzero-compromise.md, nor a governance-relay misconfiguration like the examples/2023-2024-layerzero-governance-relay-misconfiguration-audit-cohort.md cohort. It is an operator role's hot wallets being emptied, and the loss stayed at gas-float scale because that is what the role holds. Contributors updating this entry when detail emerges should add the entry-vector technique against a confirmed source, replace the range with final accounting, and preserve the co-location finding independently — it is established by the chain data and does not depend on how the attacker got in.

Techniques demonstrated (2)