defirisk.co
rubric v1.7.0

Bridge uses same key custody for >30% validators

Stargate Finance's assessment for RD-F-156 — scored gray on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.

Evidence summary #

Bridge uses same key custody for > 30% of validators | Concerning but not definitively red: LayerZero Labs controls the OApp admin role AND is one of two required DVNs. Post-acquisition (Aug 2025), LayerZero Labs has full administrative power over Stargate AND is a required attestor. This is effectively >50% of the security model concentrated in one entity. While LayerZero Labs and their DVN infrastructure are separate from the OApp admin, the acquisition means the same corporate entity contr...

Sources #

  • Curator note
    Extracted from 03-oracle-deps.md — RD-F-156; no URL citedretrieved 2026-04-28

Methodology #

Determine whether >30% of bridge validators share a single key custodian.

See the full factor methodology and distribution across all protocols →

rubric_version v1.7.0 protocol stargate factor RD-F-156 score gray collected_at 2026-04-28 01:38:41