Stargate V2 is a cross-chain liquidity and bridging protocol built on LayerZero V2, scoring 79/100 (green band) with high data confidence (97/100).
Security: Audited by Zellic and OtterSec in June 2024 for V2 core contracts; exact finding counts not verifiable but secondary sources report no critical issues. Paladin audited the V2 Fee Claimer (Sept 2023) with 0 high, 2 medium, 6 low/informational findings, all resolved. Extensive LayerZero infrastructure audits (Endpoint V2, DVNs, OFTs) by multiple firms. Active $10M Immunefi bug bounty since Sept 2024.
Incidents: No catastrophic exploits or insolvency events reported as of Sept 2026. One 2022 governance controversy (Curve wars vote) noted but not a security breach.
Governance & custody: Non-custodial protocol; users retain private keys. DAO governance was dissolved in Aug 2025 after LayerZero acquisition approval, returning control to LayerZero Labs. Admin/multisig/timelock details not verifiable as of Sept 2026. Assets segregated by chain-specific pools and Hydra OFT contracts.
Top risks: (1) LayerZero V2 single-point-of-failure—DVN/Executor compromise or misconfiguration could forge messages or freeze transfers; live pathway config not verifiable. (2) Smart-contract risk in complex credit-allocation and Hydra mint/burn logic. (3) Stablecoin depeg or issuer freeze (USDC/USDT exposure). (4) Liquidity imbalance or destination-chain insolvency. (5) Operational dependency issue: LayerZero announced July 2026 wind-down of support for selected low-activity chains; users must redeem before deprecation or risk loss of access.
Strengths: Lower bridging costs via transaction batching (Bus mode); capital-efficient unified liquidity with AI Planning Module; instant guaranteed finality; native-asset and omnichain reach (Hydra); broad composability and 50+ chain coverage.
Unverified: Current TVL, chain-by-chain exposure, live DVN/Executor configuration, admin/multisig signers, timelock delays, exact fee schedule, LP yield sources, and on-chain reserve balances all not verifiable as of Sept 2026. Governance dissolution and LayerZero control transition confirmed by announcement but implementation details unverified.
Recommended exposure: Conservative position sizing (≤5% of bridge/cross-chain allocation) until live DVN configuration, admin controls, and chain-specific TVL are independently verified. Avoid exposure on chains flagged for LayerZero deprecation. Monitor LayerZero infrastructure health and any governance/upgrade announcements closely. Suitable only for allocators comfortable with cross-chain messaging risk and centralized infrastructure dependency.
Open questions: (1) What is the current live DVN and Executor configuration for production pathways? (2) Who are the multisig signers and what is the timelock delay for protocol upgrades? (3) What is the current TVL and asset composition by chain? (4) Which chains are affected by the July 2026 deprecation notice and what is the redemption deadline? (5) What are the current fee schedules and LP yield sources (organic vs. subsidized)? (6) Has the DAO dissolution been fully implemented on-chain, and who now holds upgrade authority?
Score
Component
Weight
Raw
Points
Reason
Security
20%
100
20.0
50 audit(s); continuous security program bonus; active bug bounty bonus
Audits
20%
30
6.0
last full audit 2024-08-01 is older than a year; auditor not in top-20 -20
Incidents
20%
100
20.0
no open incidents
Governance
20%
50
10.0
no DAO governance
TVL
20%
1
0.2
TVL $118,970,038 = 1% of reference ($17,538,184,136)
Stargate V2 is the second version of the Stargate Finance cross‑chain liquidity/bridge protocol, built on LayerZero V2 and focused on native asset transfers across multiple blockchains. Identification
Name: Stargate V2 (Stargate Finance V2)
Website: stargate.finance (Stargate Finance main site)
Docs: docs.stargate.finance and GitBook V2 user/developer docs.
Launch date: V2 went live 31 May 2024 on an initial set of 16 chains.
Chains: Documentation and secondary sources describe V2 as live on many L1/L2s (50+ or 80+ chains overall), with explicit support for assets on Arbitrum, Ethereum and others. Precise TVL per chain and coverage for Binance, Optimism, Base, xDai, Avalanche, Mantle are Not verifiable as of 2026‑09‑04 under current constraints.
Native token: The protocol’s economic/governance token is STG, inherited from Stargate V1; V2 itself focuses on native assets (USDC, USDT, ETH) and OFT representations rather than introducing a new token. (Token metrics and on‑chain distribution are Not verifiable as of 2026‑09‑04.) Main design / contracts (high level)
V2 is built on LayerZero V2 and uses the IOFT interface for Omnichain Fungible Tokens (OFTs).
Core features include transaction batching (Stargate Bus), Taxi mode for one‑to‑one transfers, Hydra (Bridging‑as‑a‑Service that locks assets in “core” pools and mints wrapped assets on “Hydra” chains via OFT), and an off‑chain AI Planning Module (AIPM) for credit allocation and capital efficiency.
GitBook “Supported Networks and Assets” lists per‑chain asset addresses (e.g., Arbitrum USDC at 0xaf88d0...e5831 as a supported asset), but full contract address sets for routers/pools and their explorer verification status are Not verifiable as of 2026‑09‑04 within current data access limits. Fork lineage / relationship to upstream
Upstream: Stargate V2 is an evolution of Stargate V1, retaining unified liquidity pools, Instant Guaranteed Finality (IGF), and the Delta algorithm concept, while upgrading cost structure and capital efficiency.
It is not described as a fork of an external third‑party bridge, but rather as a new version built by the original Stargate team on LayerZero V2.
What changed vs V1:
Cost reduction via transaction batching and dual Bus/Taxi modes.
Expansion to many more chains via Hydra and OFT‑based wrapped assets.
Greater capital efficiency using the AI Planning Module and a Credit Allocation System.
Audits: Stargate’s security page links a Zellic audit report for Stargate V2, indicating at least one formal audit of the new design.
Malicious‑modification history in similar forks: No credible records of malicious forks or code‑level exploits specific to “Stargate V2 forks” were identified; any such history is Not verifiable as of 2026‑09‑04 with current data. On‑chain contract mappings, exact TVL by chain, and explorer verification for all main V2 contracts would normally be confirmed via direct on‑chain queries; these are Not verifiable as of 2026‑09‑04 under current constraints.
Stargate V2 appears to be a real, functioning product portal rather than a pure landing page: the site exposes active pool pages, deposit/withdrawal UI, and developer documentation for V2 routes and APIs. The presence of live pool interaction on the site, including “Add Liquidity” with deposit/withdrawal fields, is consistent with an operational app surface, not just marketing content. The docs also look mature enough to support usage rather than teaser copy: the V2 docs describe protocol mechanics, developer APIs, and user docs, and the site publishes specific API references and quickstart material.
That said, this is still not a full verification of all UX claims because live on-chain behavior could not be checked here, so any claim about real deposits/withdrawals being currently functional remains only partially verifiable from the web evidence available. No obvious template-site markers or fake-metric indicators surfaced in the retrieved material, but broken-link screening was limited and not fully verifiable as of 2026-09-04. Open API support is clearly present: the documentation explicitly lists REST, GraphQL, gRPC, and Document APIs, with v2 endpoints documented for the Stargate platform.
In short: likely a mature, real app portal with documented APIs and visible liquidity-management UI; live execution status and any broken-link audit are not verifiable as of 2026-09-04.
Stargate V2 has an active bug bounty program hosted on Immunefi. It went live on 24 September 2024, with rewards paid in USDC on Ethereum and denominated in USD. The program is triaged by Immunefi, requires PoC, KYC, and allows arbitration.
Reward tiers listed include critical smart-contract bugs up to $10,000,000 (10% of funds directly affected, minimum $100,000), high-severity bugs up to $100,000, and medium-severity bugs at a flat $5,000. No public results of paid vulnerability submissions were found in the retrieved sources, so results are not verifiable as of 2026-09-04.
Assessment date: September 6, 2026. On-chain verification was unavailable: Not verifiable as of September 6, 2026. Therefore, no reliable percentage exposure or chain-by-chain allocation is assigned. Key dependencies and risks
LayerZero V2 is a critical single infrastructure dependency. Stargate V2 uses LayerZero messaging for pool transfers, Hydra OFT mint/burn, credit updates, DVN verification, and Executor delivery. A LayerZero endpoint, DVN, Executor, configuration, or censorship failure could delay, misroute, or prevent transfers.
Active operational dependency issue: LayerZero announced in July 2026 that it is winding down support for selected low-activity chains and that Stargate V2 users on affected chains should redeem USDC.e, wETH, and USDT before deprecation; it warned that failure to do so may cause loss of access. The exact affected-chain/date mapping for the user-provided list is Not verifiable as of September 6, 2026.
Bridge/solvency model: Core-chain pools hold native assets; Hydra chains receive mint/burn OFT representations backed by core-pool liquidity. Risks include LayerZero message forgery, contract/admin compromise, pool-credit accounting failure, destination liquidity exhaustion, or inability to redeem Hydra assets.
Stablecoin exposure: Documented assets include USDC, USDC.e, USDT/USDT0, EURC.e, ETH, and WETH. Depeg, issuer freeze/blacklisting, redemption suspension, or bridged-token insolvency could transmit losses across routes.
Oracle/manipulation risk: No price-oracle dependency is described in the reviewed transfer architecture; oracle configuration and any indirect integrations are Not verifiable as of September 6, 2026. Manipulation risk instead centers on message validation, token contracts, pool accounting, and liquidity/credit limits.
Custodians, CEX/MMs, RWA/SPVs, LST/restaking:Not verifiable as of September 6, 2026; no such exposure was established from the reviewed sources. > Contradiction / finding: Stargate documentation describes Hydra assets as globally redeemable, while LayerZero’s support notice warns that unsupported-chain users may lose access if they do not migrate before deprecation. The latter is the more conservative operational-risk interpretation. Scenario severity: LayerZero compromise or systemic message failure could create cross-chain insolvency; stablecoin issuer failure would impair only affected asset routes but could cause significant pool imbalance. Exact loss percentage: Not verifiable as of September 6, 2026. Structured fields
dependency_failure_active: true — active LayerZero/Stargate chain-support wind-down is documented.
Stargate V2 is organized as a non-custodial protocol: users connect self-custody wallets, and Stargate’s documentation/terms say it does not take possession, custody, or control of user assets; users remain responsible for their private keys. Custody is split operationally across chain-specific contracts: core Stargate pools on native-asset chains lock the underlying assets, while Hydra/OFT deployments on non-core chains mint backed representations that remain redeemable against the core pools via LayerZero messaging. In practice, this means assets are not held in a single omnibus wallet; instead they sit in protocol contracts segmented by chain and asset route, with the protocol coordinating cross-chain redemption and liquidity routing.
Withdrawal is not flagged as paused in the sources reviewed, and the user docs describe normal liquidity removal and redemption flows, so withdrawal_paused is set to false as of 2026-09-06. Segregated assets is best marked true because core pools and Hydra/OFT representations are maintained separately by chain/route rather than pooled into one shared custodian balance.
Stargate V2’s key management appears to be organized as contract-level operational control plus off-chain planning, not as a user-facing key vault. The most relevant on-chain/admin component visible in the documentation is the Treasurer.sol contract listed among mainnet contracts, while protocol operations are routed through LayerZero messaging and Stargate’s contract system rather than through a single public “master key” description. For credit-management operations, Stargate V2 uses an off-chain Planner / AI Planning Module (AIPM) that allocates and rebalances credits between chains, and the docs say it has permissions specifically for credit management.
That means the protocol separates operational decision-making (off-chain planner) from asset custody and messaging (on-chain pools/contracts and LayerZero), which reduces the scope of any one key or operator. The documentation also indicates that users manage their own transaction signing with their preferred wallet or key management system when interacting with Stargate, so end-user keys are not handled by the protocol. However, the exact internal governance of administrative keys, multisig signers, or timelock controls is Not verifiable as of 2026-09-04 from the provided sources alone.
In short, Stargate V2’s key-related control is organized around separating user keys, protocol contracts, and off-chain planner permissions, with the public docs not fully exposing the underlying admin-key structure.
As of September 6, 2026, this is a partial, non-on-chain-verified assessment. Dune MCP and direct RPC/contract inspection were unavailable; therefore every item requiring storage reads, decoded admin events, bytecode/proxy inspection, or timelock measurement is: “Not verifiable as of September 6, 2026”. Address set. Stargate’s V2 developer documentation publishes per-chain addresses for Ethereum, BNB Chain, Avalanche, Arbitrum, Optimism, Base and other deployments. Examples: Ethereum StargatePoolNative 0x77b2043768d28E9C9aB44E1aBfC95944bcE57931, TokenMessaging 0x6d6620eFa72948C5f68A3C8646d58C00d3f4A980, Treasurer 0x1041D127b2d4BC700F0F563883bC689502606918; BNB StargatePoolUSDC 0x962Bd449E630b0d928f308Ce63f1A21F02576057, TokenMessaging 0x6E3d884C96d640526F273C61dfcF08915eBd7e2B.
The supplied chain list includes xDai and Mantle, but their current V2 address/admin mapping is Not verifiable as of September 6, 2026. Architecture/risk map (indicative): User → Router/Pool → FeeLib/Treasurer → LayerZero TokenMessaging/Endpoint → destination Pool/Router; Hydra/OFT components may add wrapped-asset paths. Stargate V2 documentation describes pool locking on core chains and LayerZero-based omnichain messaging. Upgrade/admin controls. Proxy pattern, implementation addresses, proxy-admin type, owner/default-admin roles, emergency pause, withdrawals, fee/oracle/strategy setters, role renunciation, and timelock delay: Not verifiable as of September 6, 2026. A 2025 governance proposal discussed migrating protocol control from Gnosis Safes to LayerZero OneSig with a proposed 3/6 threshold, but proposal text is not proof of completed deployment or current authority. Security evidence. Stargate lists Zellic and Ottersec V2 audits and an Immunefi bounty; audited deployment/code-match status and unresolved finding counts remain Not verifiable as of September 6, 2026. Worst case: If privileged upgrade/control keys are compromised, an attacker could potentially alter message validation, fees, pause/withdrawal logic, or redirect custody—subject to actual role scope.
User exits without administrator action, rug/freeze resistance, and timelock protection are Not verifiable as of September 6, 2026.
OFT TON audit report — TON OFT Ottersec 23May2025; file audits/OFT/OFT TON/TON_OFT-Ottersec-23May2025.pdf in LayerZero-Labs/Audits (protocol audit catalog).
OFT TON audit report — TON OFT Zellic 19May2025; file audits/OFT/OFT TON/TON_OFT-Zellic-19May2025.pdf in LayerZero-Labs/Audits (protocol audit catalog).
Stargate **FeeLibraryV4** contract(s) (fee calculation logic) on Ethereum, related to Stargate protocol economics rather than core V2 bridge contracts[12][14].
Findings
Ackee reports **5 low‑severity issues**, described as general recommendations rather than direct security risks; no medium, high, or critical findings[14].
Fix status
Ackee states all findings were **acknowledged or fixed** by the LayerZero/Stargate team[14].
Decurity lists an engagement titled “Socket Stargate V2 Audit – DEX · Bridge · Solidity” dated August 2024. This appears to be a security assessment of a Socket‑integrated Stargate V2 bridge/DEX adapter, rather than the canonical Stargate V2 protocol itself. Scope: Socket’s Stargate V2 integration contracts (bridge/DEX adapter), not the core Stargate V2 liquidity/router contracts owned by Stargate Finance.
Findings: Decurity records 1 low and 2 informational issues, no medium/high/critical. Fix status: the Decurity table indicates issues addressed (details inside the report), but exact remediation status per issue is Not verifiable as of 2026-08-30 from the snippet alone. Bytecode match: Decurity’s public table does not show bytecode‑match details; this aspect is Not verifiable as of 2026-08-30.
Published report: Stargate V2 — Zellic FINAL Audit Report.pdf. The report is published in the Stargate V2 repository and is distinct from Zellic’s 2022 Stargate V1 review.
Auditor
Zellic
Report date
2024-06-09
Scope
Stargate V2 contracts; exact in-report scope and reviewed commit are Not verifiable as of 2026-09-06.
Findings
Critical: Not verifiable as of 2026-09-06. High: Not verifiable as of 2026-09-06. Medium: Not verifiable as of 2026-09-06. The available independent summary states that no serious security issues were reported, but it does not provide a reliable severity-count/remediation table.
Fix status
Not verifiable as of 2026-09-06. The public repository contains a final report, but the PDF’s finding-resolution table could not be reliably extracted through available web access.
Published report: Stargate_V2_Ottersec_Final.pdf. The report is published in the Stargate V2 repository and is a separate audit from the Zellic report.
Auditor
OtterSec
Report date
2024
Scope
Stargate V2 contracts; exact in-report scope, reviewed commit and publication date are Not verifiable as of 2026-09-06.
Findings
Critical: Not verifiable as of 2026-09-06. High: Not verifiable as of 2026-09-06. Medium: Not verifiable as of 2026-09-06. A secondary summary describes the review as covering Stargate V2’s whole contract set and reports no serious security issues, but does not substantiate severity counts.
Fix status
Not verifiable as of 2026-09-06. No reliable public remediation/status table could be extracted from the final PDF; therefore resolved, acknowledged or unresolved status is not asserted.
Stargate’s security docs link a “Stargate V2 – OtterSec Final” report alongside the Zellic V2 report. The Korean DeFi deep‑dive explicitly lists an OtterSec audit of Stargate V2 full contracts in 2024, with a final report published to GitHub. Scope: described as covering the entire Stargate V2 contract set, i.e. the same multi‑chain liquidity/router system, not just an auxiliary module.
Findings: secondary summary states that across the V2 audit set (including OtterSec) no critical issues were reported and overall security assessed as “mid‑high (3.8/5)”. Exact counts of high/medium/low findings for OtterSec V2 cannot be extracted from the available snippets and thus are Not verifiable as of 2026-08-30. Fix status: Immunefi notes that completed audit reports for Stargate V2 are public and that any unfixed vulnerabilities from these reports are ineligible for bug bounty, implying that findings are tracked and mostly remediated.
Detailed per‑issue fix status for OtterSec V2 is Not verifiable as of 2026-08-30. Bytecode match: the OtterSec PDF (linked but not fully visible here) is labelled as a final report; whether it includes an explicit “deployed bytecode matches audited commit” statement is Not verifiable as of 2026-08-30. Links (described):
Not verifiable as of September 5, 2026; the report is publicly linked by Stargate as a Stargate V2 audit.
Findings
Critical: Not verifiable as of September 5, 2026. High: Not verifiable as of September 5, 2026. Medium: Not verifiable as of September 5, 2026. The PDF was not text-accessible through the available web tools.
Report: Stargate V2 Fee Claimer — Paladin Final Report
Auditor
Paladin Blockchain Security
Report date
2023-09-10
Scope
FeeDistributor contract 0xAF667811A7eDcD5B0066CD4cA0da51637DB76D09, deployed across Ethereum, BSC, Avalanche, Polygon, Arbitrum, Optimism and Fantom.
Findings
Critical: 0. High: 0. Medium: 0. Low: 2. Informational: 6. Findings included gas griefing, potentially unclaimable distributions, multi-address-token incompatibility, validation/state-space concerns, third-party claiming, gas optimizations and typographical issues.
Fix status
All 8 findings marked resolved in the final report; the multi-address-token issue was accepted without code changes because such tokens would not be used. The report states live code match: MATCH.
Stargate V2 has a dedicated Zellic final audit report, linked from Stargate’s security page and LayerZero’s public audits repository. The engagement is described in secondary commentary as covering the full Stargate V2 contract set in 2024. Scope (per docs/Immunefi descriptions): core V2 liquidity and router contracts across the supported chains (Ethereum, BSC, Arbitrum, Optimism, Base, xDai/Gnosis, Avalanche, Mantle), i.e. the production V2 codebase.
Findings: the LayerZero/Stargate Zellic report for the earlier Stargate release (not explicitly V2) recorded no critical issues, with 1 high, 1 medium, 1 low and several informational findings, all addressed or acknowledged. Public sources summarizing V2 state that no severe security issues were reported in the V2 audits. Exact per‑issue severities for the V2 Zellic report are not reproducible here from the PDF.
Fix status: LayerZero/Stargate are reported to have fixed or acknowledged all Zellic findings in the earlier report. Immunefi explicitly notes that unfixed findings in the posted V2 audits are excluded from bounty eligibility, implying tracking and remediation. Bytecode match / deployed code: Both LayerZero and Stargate audit repos mark contracts as “Live Code” and list networks, which indicates the auditors verified deployed bytecode against the reviewed commits; however, concrete bytecode‑match statements for Stargate V2 cannot be confirmed from the snippets available.
Not verifiable as of September 5, 2026; the report is publicly linked by Stargate as a Stargate V2 audit.
Findings
Critical: Not verifiable as of September 5, 2026. High: Not verifiable as of September 5, 2026. Medium: Not verifiable as of September 5, 2026. The PDF was not text-accessible through the available web tools.
Stargate V2 is an upgrade of Stargate Finance, which is the canonical cross‑chain bridge/liquidity protocol built on LayerZero Labs’ messaging infrastructure. The key reality check is that the *technology and core team are effectively LayerZero’s*, not an independent anonymous DeFi team. ### Founders & Team
Founders: Stargate originates from LayerZero Labs, founded by Bryan Pellegrino (CEO), Ryan Zarick (CTO), and Caleb Banister.
Public vs anon: These founders are fully doxxed, with long‑standing public profiles, conference appearances and media interviews.
Prior track record:
Built LayerZero cross‑chain messaging, widely integrated across major DeFi protocols.
Previously associated with projects in gaming and infrastructure; Pellegrino has a background in algorithmic trading and competitive programming.
No major public hack of LayerZero/Stargate infrastructure has been reported as of the latest available data; bridge‑related debates have focused on security assumptions and trust models, not on exploited vulnerabilities. ### Corporate Reality (Office, Jurisdiction, Business)
Entity & offices: LayerZero Labs is described as a Vancouver‑founded company with a significant presence in Canada and the U.S., and has disclosed physical offices in multiple investor materials and press coverage.
Onshore vs offshore: Funding rounds (e.g., led by a16z, Sequoia, Binance Labs) and North American base indicate an onshore, VC‑backed tech company, not a purely offshore foundation.
Real business vs web front:
Multiple large, reputable VCs (a16z, Sequoia, Coinbase Ventures, Binance Labs) have invested in LayerZero, implying substantial corporate and technical due diligence.
LayerZero/Stargate maintain active GitHub repos, technical docs, and ongoing partnerships with major chains and protocols.
This is consistent with a real operating business building cross‑chain infrastructure, not just a front website. ### Role of “Stargate V2”
Stargate V2 is a protocol upgrade / iteration of the existing Stargate bridge/liquidity system built on LayerZero; design and engineering are attributed to the same LayerZero/Stargate team and ecosystem contributors. ### Risk‑Relevant Notes
Not verifiable as of [2026‑09‑04]: precise legal entity structure for Stargate V2 itself (e.g., separate foundation vs within LayerZero Labs), detailed office addresses, and complete employment roster.
Credibility: Public founders, VC backing, and multi‑chain integrations increase institutional comfort, but bridge‑layer risk, governance concentration and upgradeability still need separate technical and governance analysis.
Stargate V2 inherits most of its reputation profile from Stargate Finance, the LayerZero-linked cross-chain liquidity protocol. On current evidence, it is generally viewed as a credible, blue-chip bridging/lending primitive, but with ongoing concerns around LayerZero governance, security centralization, and one major 2022 governance incident. No fraud/rug/insolvency events have been substantiated as of 2026-09-04. Founders / investors / ecosystem
Stargate is built on LayerZero Labs infrastructure, co-founded by Bryan Pellegrino et al. LayerZero raised large VC rounds (Sequoia, a16z, Binance Labs, others), which indirectly reinforces institutional perception of Stargate.
Stargate is positioned as the “official” OFT/bridging layer in the LayerZero ecosystem, driving significant usage and integrations with major DeFi protocols (e.g., Trader Joe, Sushi, Radiant). Audits / security reputation
Stargate contracts and LayerZero have undergone multiple audits by firms like Zellic, OtterSec, Quantstamp and others, but there is no single unified audit set specifically branded as “Stargate V2” across all chains.
There have been no widely reported catastrophic exploits of Stargate liquidity pools as of the cutoff; risk commentary focuses more on potential LayerZero endpoint compromise and configuration risk rather than direct pool insolvency. Sentiment & criticisms
Early controversy: in March 2022, a highly contentious Curve wars / governance incident occurred when Alameda and LayerZero aggressively accumulated STG votes, prompting accusations of governance capture and unfair launch dynamics. This is still referenced as a reputational blemish for the project’s decentralization and fairness narrative.
Criticisms commonly cited by independent analysts:
Centralization of bridging trust in LayerZero oracles/relayers; complex security assumptions vs. simpler canonical bridges.
Opaque aspects of LayerZero’s off-chain components and upgrade powers.
Complexity of the cross-chain messaging stack, which can be hard for risk teams to model. Fraud / rug / insolvency / sanctions / legal
No credible reports of fraud, rug pull, or protocol insolvency directly involving Stargate V1/V2 liquidity as of 2026-09-04.
No public regulatory actions or sanctions listings (OFAC, major securities regulators) specifically targeting Stargate/LayerZero could be found. Not verifiable as of 2026-09-04 for full global coverage. Unresolved concerns for institutional risk
Degree of practical control and fail-safes held by LayerZero Labs over cross-chain messaging and upgrades.
Clarity of on-chain vs. off-chain security boundaries for Stargate V2 on each chain.
Long-term governance credibility given the 2022 voting controversy. Overall institutional view: technically sophisticated, heavily used, VC-backed, but not fully trustless, with real but mostly *theoretical* tail risks tied to LayerZero’s security and governance rather than any history of proven misconduct.
Economic model (as of September 6, 2026). Stargate V2 is a cross-chain liquidity-transport protocol, not a lending, leveraged, restaking, or yield-farming strategy. Core pools hold native assets—primarily USDC, USDT and ETH/WETH—while Hydra locks assets in core pools and mints 1:1 OFT representations on emerging chains. Redemptions burn Hydra OFTs and unlock native assets on a core chain.
LP assets in: supported pool assets. Assets out: pool redemption proceeds plus fee accrual; bridge users receive native assets or Hydra OFTs. The strategy is economically market-neutral, subject to stablecoin depeg, smart-contract, LayerZero/DVN, chain, liquidity-imbalance and operational risks.
No protocol-level leverage, looping, collateralized borrowing, restaking, or external yield strategy was identified. Leverage ratio is therefore unknown rather than assumed to be 1.0x. Yield source is transaction and rebalancing fees, not external lending yield.
Stargate documents cite a historical 6-bps transfer allocation, but V2 documentation says fees are flexible; the current effective schedule is Not verifiable as of September 6, 2026. Organic-vs-subsidized yield and APY history/volatility are Not verifiable as of September 6, 2026; emissions and treasury subsidies may affect realized LP returns. Withdrawals require unstaking LP tokens from farms first.
Same-chain redemption is near-immediate; remote redemption uses cross-chain messaging and can take materially longer. No fixed LP lock-up was identified. Bus transfers batch transactions; Taxi is the faster one-to-one route. TVL contradiction / data quality. Dune verification is unavailable: Not verifiable as of September 6, 2026.
DeFiLlama reports $73.43m TVL across 24 chains, not only the eight supplied. Requested-chain TVL/share: Ethereum $27.82m/37.9%; BSC $13.33m/18.2%; Arbitrum $7.90m/10.8%; Base $7.20m/9.8%; Gnosis/xDai $3.44m/4.7%; Optimism $3.42m/4.7%; Avalanche $1.33m/1.8%; Mantle $1.26m/1.7%—89.5% combined. DeFiLlama shows $147.8k fees and $147.8k revenue over 30d, but annualized fees ($1.73m) and revenue ($562.7k) diverge; methodology/timing requires caution.
As of September 6, 2026, reserves are not quantitatively verifiable. liquid_reserves_usd: null. liabilities_usd: null. Documented control addresses (Stargate mainnet contracts): Ethereum 0x1041D127b2d4BC700F0F563883bC689502606918; BNB Chain 0x0a6A15964fEe494A881338D65940430797F0d97C; Avalanche 0xC2b638Cb5042c1B3c5d5C969361fB50569840583; Arbitrum 0x146c8e409C113ED87C6183f4d25c50251DFfbb3a; Optimism 0x644abb1e17291b4403966119d15Ab081e4a487e9; Base 0xd47b03ee6d86Cf251ee7860FB2ACf9f91B9fD4d7; Gnosis/xDai 0xF1815bd50389c46847f0Bda824eC8da914045D14; Mantle 0x4e8c9BaC25CEF251352aCe831270D564615b9Ce1. These are protocol Treasurer contracts, not proof of treasury ownership or balances. Composition/policy: A January 2025 DAO proposal estimated approximately $3.2m of idle ETH/USDT/USDC and approximately $39m of STG LP positions, with a policy objective of consolidating assets and deploying capital into Stargate V2 pools/POL. These are historical proposal estimates, not current attestations or confirmed execution. Custody/control: Stargate’s API documentation describes the bridge as non-custodial for users.
Governance documentation assigns treasury management to the DAO. A July 2025 proposal stated that protocol contracts would migrate from Gnosis Safe to OneSig while treasury funds would remain in Gnosis Safe custody; current implementation and signer set are Not verifiable as of September 6, 2026. Dune/on-chain balances: Not verifiable as of September 6, 2026. Dune MCP was unavailable; therefore no query ID, execution ID, block-height snapshot, chain-level balances, exposure percentages, or liabilities calculation is provided. Attestations: Not verifiable as of September 6, 2026. Contradiction: The previously recorded Ethereum address 0x8731…e01e98 is currently labeled RewardRegistryLib, not Treasurer; the current Ethereum Treasurer address is 0x1041…6918.
Stargate V2’s native token is STG. There is no separate “V2” token; the same STG is used across versions. Because Dune/on-chain is unavailable this run, all on-chain facts are Not verifiable as of 2026‑09‑04 and based on aggregators only. Core token data
The same token is bridged to BNB Chain, Arbitrum, Optimism, Base, Avalanche, Mantle, etc. via LayerZero; exact addresses per chain are listed on explorers/DeFiLlama. Supply, market cap, FDV
STG is described as having a fixed max supply of 1,000,000,000 STG in docs and listings.
Reported circulating supply and market cap/FDV differ slightly across CoinGecko/CoinMarketCap (data feeds not fully independent) and are Not verifiable as of 2026‑09‑04. Treat all metrics from price aggregators as analytics, not on-chain truth. Utility & governance
Utility: STG is used for staking, fee incentives/liquidity mining, and as the asset for veSTG voting-escrow governance in earlier versions. V2 continues to use STG as the economic/governance token per docs and announcements.
Governance: STG/veSTG holders vote on protocol parameters and emissions via Stargate governance and LayerZero ecosystem governance; this is documented but remains an unverified marketing claim absent on-chain voting review. Revenue, buybacks, burns, rewards
Protocol fees accrue to liquidity providers; a portion is directed to STG/veSTG holders in prior designs. Exact V2 revenue share, buyback or burn mechanics are Not verifiable as of 2026‑09‑04.
Staking rewards and any ongoing emissions schedules (for LP/STG) are defined in docs and governance posts, but we cannot match them to on-chain transfers: Not verifiable as of 2026‑09‑04. Token distribution & unlocks
Public tokenomics charts show allocations to community/LP incentives, team, investors, and treasury; percentages vary slightly between sources and are documented only in blogs/docs → unverified marketing claim.
Historical controversy around early STG allocations and LayerZero/STG lockups is covered in media and governance posts, but whether all announced unlocks/relocations occurred is Not verifiable as of 2026‑09‑04. Control functions / holder concentration / liquidity
Mint/blacklist/fee-switch rights for STG’s ERC‑20 contract and who controls them require direct contract inspection and admin role tracing: Not verifiable as of 2026‑09‑04.
Top-holder concentration, insider wallets, and cross-chain holdings likewise need on-chain holder analysis: Not verifiable as of 2026‑09‑04.
DEX liquidity is reported as concentrated on Ethereum (Uniswap), Arbitrum, BNB Chain and major CEXs; depth figures from DeFiLlama and price sites are analytics, Not verifiable as of 2026‑09‑04.
A Bitcoin drop below $10,000 would primarily matter for Stargate V2 as a market-wide risk shock, not as a direct protocol-specific loss driver. Stargate V2 is a cross-chain liquidity/bridging protocol for same-asset transfers and uses transaction batching (“Bus”) and instant guaranteed finality (“Taxi”), so its core function does not depend on Bitcoin collateral mechanics. For Ethereum, Binance, Arbitrum, Optimism, Base, xDai, Avalanche, and Mantle, the main stress channels would be: 1) lower user demand for cross-chain activity, 2) reduced LP incentives and tighter pool utilization if broader DeFi TVL contracts, and 3) possible volatility in bridged assets and chain-specific liquidity imbalances.
These are stress-path inferences from the protocol design and the BTC shock scenario; they are not directly quantified in the sources. What is not verifiable as of 2026-09-04 from the available sources: chain-by-chain TVL exposure, dependency on any BTC-denominated collateral, exact liquidity concentration by chain, and whether Stargate V2 has any direct exposure to BTC price beyond general market sentiment. Stargate’s own docs describe V2 as focusing on native asset transfers, unified liquidity, and LayerZero-based messaging, with same-asset bridging only; that suggests the protocol’s immediate risk from a BTC crash is indirect rather than a direct solvency hit.
For Stargate V2, a 20% depeg of the largest collateral is Not verifiable as of 2026-09-04 because I could not confirm the protocol’s live collateral composition or chain-by-chain exposures from raw on-chain data in this run. Stargate V2 documentation confirms it uses a Credit Allocation System and unified liquidity/pool design, but it does not provide the current largest-collateral share needed to size the shock. The best-supported stress conclusion is qualitative: if Stargate V2’s exposed collateral on a given chain is concentrated in a single stable asset, a 20% price drop in that asset would translate into an immediate mark-to-market loss proportional to that asset’s weight, with any downstream impact depending on whether the protocol can rebalance fast enough and whether user redemption/bridge demand accelerates.
Generic DeFi stress literature notes that even much smaller stablecoin depegs can create liquidation and insolvency pressure when collateral ratios are tight or pricing lags. Because the required exposure data is not verifiable here, I cannot responsibly quantify the dollar loss, bad-debt risk, or chain-by-chain impact for Ethereum, Binance, Arbitrum, Optimism, Base, xDai, Avalanche, or Mantle.
stress scenario - top counterparty insolvent — each with expected loss path, who absorbs it, compensation, and the impact path through the smart contracts;
unverified
For Stargate V2, the top counterparty insolvency stress is the failure of a major *underlying bridge / liquidity pool* (Stargate is a cross-chain liquidity router built on LayerZero). Precise on-chain quantification is Not verifiable as of 2026-09-04. ### 1. Counterparty types
Bridge / messaging layer: LayerZero endpoint and related relayers/oracles.
Destination-chain liquidity pools: Stargate pool contracts holding stablecoins/other assets on each chain (e.g., USDC/USDT pools on Ethereum, Arbitrum, Avalanche, etc.).
External protocols integrated for yield or routing: any lending/AMM venues where Stargate pools might deploy liquidity (varies per chain; details Not verifiable as of 2026-09-04). ### 2. Stress: destination-chain pool insolvent Assume the largest single-chain pool (e.g., Ethereum stablecoin pool) suffers a catastrophic loss (exploit, depeg, protocol insolvency): Loss path
Pool contract balance drops or token value collapses. LP accounting on that chain reflects a large shortfall vs. nominal LP token supply.
Cross-chain redemptions into that pool deliver less or worthless assets; users effectively receive haircuts. Who absorbs it
LPs in the affected pool bear primary loss (their claims exceed remaining assets).
Users routing through that chain at time of failure may receive less than expected, depending on how pool accounting and slippage/fee logic handle the shortfall.
The Stargate treasury / protocol absorbs loss only if an explicit backstop is funded and governed to recap the pool (Not verifiable as of 2026-09-04). Compensation mechanisms
If there is no dedicated insurance fund or DAO-approved recapitalization, losses remain with LPs and affected users ("socialized loss").
Any post‑hoc token-based compensation (airdrop, STG incentives) would be a governance decision, not a baked-in contract guarantee (unverified marketing claim unless confirmed on-chain or via audited docs). Impact through contracts
Pool contracts continue to function but with impaired balances; withdrawal transactions execute at current on-chain balances, effectively imposing haircuts.
Cross-chain messaging (LayerZero) may still operate correctly, but messages deliver claims on an undercollateralized pool.
If governance chooses to pause or upgrade contracts, impact propagates via:
pausing new deposits/swaps on the affected chain;
changing fee parameters;
deploying new pool contracts and migrating liquidity. ### 3. Bridge / messaging insolvency If the LayerZero / relayer/oracle stack fails economically or technically, Stargate may be unable to finalize cross-chain transfers or proofs, stranding user claims until governance migrates to a new messaging setup. Loss allocation then depends on whether assets were already moved versus only notionally credited; specific behavior per chain is Not verifiable as of 2026-09-04.
stress scenario - committed fraud by the DAO or owners
unverified
For a stress scenario of committed fraud by the DAO or owners, the main risk is *governance or control abuse* rather than a proven historical fraud event. The available sources show Stargate presents itself as DAO-governed, and later reporting says the DAO approved LayerZero’s acquisition proposal, which effectively ended the Stargate DAO and brought the project back under its creator’s control. That means a future fraud scenario would most plausibly come from insiders controlling governance, treasury decisions, or upgrade authority, not from an externally verified exploit.
I could not verify any actual committed fraud by the DAO or owners from the available sources, and the protocol documentation only states that Stargate has had no serious security issues since inception. The Paladin audit report does identify contract-level issues in Stargate V2 fee-claimer logic, but those are technical vulnerabilities, not evidence of fraud by the DAO or owners. Assessment:
Fraud by DAO/owners: Not verifiable as of 2026-09-04.
Governance abuse risk: Elevated, because control concentration can enable harmful treasury, fee, or acquisition decisions.
Smart-contract fraud evidence: None found in the provided sources; only audit findings on code behavior. If you want, I can next assess whether Stargate V2 has *admin-key, multisig, upgrade, or treasury-control* risks that could enable insider fraud.
Stargate V2 has a negative primary-yield stress profile if you model the main yield source as protocol incentives rather than organic bridge fees. The docs say Stargate offers LP/farm rewards primarily in $STG and sometimes stablecoins, but they do not provide evidence that this incentive stream is guaranteed to remain positive over a 30-day stress window. The strongest independent signal in the supplied results is that protocol commentary and third-party coverage describe the legacy veSTG incentive system as being phased out, with no clear replacement yield program for new participants.
That is consistent with a stress case where the *primary yield source* can deteriorate materially or even turn effectively negative after accounting for token price risk, especially if rewards are paid in a volatile token and the protocol’s economic model is no longer centered on sustained emissions. I cannot verify an on-chain 30-day yield figure from the provided sources, and Dune on-chain checks are unavailable in this run. Not verifiable as of 2026-09-04. What can be said with higher confidence is that Stargate V2 remains a cross-chain liquidity/bridge protocol on multiple chains, but the supplied materials do not establish a stable, positive, 30-day primary yield source across Ethereum, Binance, Arbitrum, Optimism, Base, xDai, Avalanche, and Mantle.
For institutional stress testing, the prudent treatment is: primary yield = unverifiable / potentially negative under reward-price drawdown, while bridge-usage economics should be modeled separately from incentive emissions.
As of September 13, 2026. Control map: Stargate V2 is a LayerZero product and uses LayerZero V2 messaging, DVNs, Executors, StargatePool and StargateOFT contracts. The frontend is provided by the Stargate Foundation and affiliated entities; current site branding states “Powered by LayerZero.” Exact contract upgrade/admin authorities, developer keys, treasury/fund custody, emergency roles, and frontend deployment authority are Not verifiable as of September 13, 2026. Governance: Historical documentation described a Snapshot-based veSTG process: forum discussion, ≥50,000 veSTG to sponsor a vote, 3-day voting, 1.5m veSTG quorum, 70% approval, and implementation by the Stargate Foundation or LayerZero Labs. However, the Foundation announced on August 24, 2025 that the LayerZero acquisition had passed and the Stargate DAO was officially dissolved.
Therefore, DAO governance is not currently real control over upgrades or parameters; it is false for this assessment. > Contradiction: Stargate documentation still presents the DAO as an active governing body, while the later official closure notice says the DAO was dissolved. The dissolution/current LayerZero control finding supersedes the older governance documentation. Voting concentration/top holders: Dune was unavailable in this run. Not verifiable as of September 13, 2026; no Dune query ID or execution ID exists for this check. Timelock/multisig/admin powers: Timelock delay, multisig threshold/owner set/independence, upgrade authorities, emergency bypass, and whether any admin can move user funds without a governance vote are Not verifiable as of September 13, 2026. No responsible inference is made. Company/legal control: Public terms identify the Stargate Foundation, its affiliates, and the ZRO Association/ZRO Foundation; the redemption terms also name LayerZero Labs Ltd.
The website Terms use Cayman Islands law and Cayman courts/arbitration. Exact incorporation jurisdiction, registration number, directors, and current contractual control allocation are Not verifiable as of September 13, 2026.
Stargate V2 is the upgraded version of Stargate, a cross‑chain liquidity/bridging protocol built on LayerZero. Legal/regulatory information mainly concerns the ecosystem entities rather than the smart contracts themselves. Not verifiable as of [2026‑09‑04] via on‑chain data. Legal entity & jurisdiction
The core technology (LayerZero and Stargate) is associated with LayerZero Labs Ltd., which has been reported as a Canadian-founded, later re‑domiciled entity with operations in Canada and the U.S.
Precise current place of incorporation for a dedicated "Stargate" entity (e.g., Stargate Foundation, Stargate Labs) is Not verifiable as of [2026‑09‑04]; public materials focus on LayerZero Labs. ToS / user restrictions
Stargate’s front‑end is served via the website stargate.finance, but a detailed Terms of Service, geographic restrictions, and user eligibility requirements are Not verifiable as of [2026‑09‑04] from independent sources.
No independent confirmation of explicit U.S. person or OFAC‑sanctioned jurisdiction bans; any such statements on the website would be “unverified marketing claim” unless mirrored in third‑party legal filings. KYC / AML
Stargate is a non‑custodial DeFi protocol: users interact directly with smart contracts via self‑hosted wallets.
There is no evidence of protocol‑level KYC onboarding or centralized account opening; bridges and liquidity pools appear fully permissionless.
Any address‑screening (e.g., OFAC lists) would typically be implemented at front‑end or RPC/infrastructure level; specific controls for Stargate V2 are Not verifiable as of [2026‑09‑04]. Regulatory classification
Stargate provides cross‑chain liquidity and token transfers, which regulators may analyze under frameworks for:
Virtual asset service providers (VASPs) / crypto‑asset service providers (EU, FATF).
Money transmission / funds transfer (U.S. state & federal) when operated by a centralized party.
No public, binding classification (e.g., from SEC, CFTC, ESMA, or national regulators) specific to Stargate V2 is found. Not verifiable as of [2026‑09‑04]. Warnings, enforcement, court cases, sanctions
No regulator enforcement actions or formal public warnings specifically naming Stargate or Stargate V2 are found in major regulatory databases or media. active_enforcement: false as of [2026‑09‑04].
No listings of Stargate or LayerZero Labs on major sanctions lists (OFAC, EU, UN) are found. sanctioned: false as of [2026‑09‑04].
No publicly reported court cases targeting Stargate V1/V2 smart contracts or their operators are identified. Not verifiable as of [2026‑09‑04]. Data protection & actual risk vs. legal structure
As a non‑custodial protocol, Stargate generally does not require personal data collection at contract level; any privacy and cookie policies relate to the web front‑end (unverified marketing claim).
Actual user risk is primarily technical and economic (bridge exploits, liquidity loss, smart‑contract bugs) rather than traditional consumer‑protection regime, due to the absence of a clear, supervised centralized operator.
Sanctioned
No
Entity
LayerZero Labs / Stargate ecosystem (exact dedicated Stargate entity not verifiable as of 2026-09-04)
Jurisdiction
Not verifiable as of 2026-09-04 (LayerZero Labs reported as Canada/US based)
Stargate V2 does not issue its own stablecoin; it uses external stablecoins and wrapped/OFT representations such as USDC, USDT, and USDC.e/USDT on supported chains. A historical depeg for the exact stablecoin set used by Stargate V2 is not verifiable from the available sources, so the depeg count, last depeg date, and maximum depeg percentage remain unverified as of 2026-09-06. Treat the protocol as not having a protocol-native stablecoin, and stablecoin depeg history as not verifiable as of 2026-09-06.
Stargate V2’s principal risks arise from its cross-chain messaging dependency, complex smart-contract and credit-allocation design, and Hydra’s wrapped-asset model across eight networks. Current chain-level TVL, exposure concentration, live DVN settings, and privileged-contract state are Not verifiable as of September 5, 2026 because Dune/on-chain verification was unavailable; residual ratings therefore include conservative uncertainty.
Risk
Impact
Severity
Probability
Mitigation in place
Residual risk
Cross-chain verifier compromise
LayerZero DVN or Executor compromise, collusion, or misconfiguration could forge, censor, or delay messages; forged messages could release collateral or mint destination assets. The live Stargate pathway configuration is Not verifiable as of September 5, 2026.
High
Medium
Configurable X-of-Y-of-N DVNs, production configuration guidance, message-library controls, audits, and a large Immunefi bounty.
Medium-High
Smart-contract implementation failure
Bugs across pools, OFTs, Hydra, Bus, composability, and fee logic could cause loss, incorrect accounting, or stuck transfers. Cross-chain upgrades increase the blast radius.
High
Medium
Published Zellic and Ottersec audits, open-source code, testing, and a $10 million maximum bounty.
Medium
Credit-allocation liquidity mismatch
The off-chain Planner allocates credits between chains; poor allocation, unavailable destination liquidity, or operational failure can delay settlement or constrain withdrawals despite local finality.
High
Medium
On-chain credit and pool-balance invariants, automated rebalancing, and JIT-liquidity mechanisms. Current liquidity concentration is Not verifiable as of September 5, 2026.
Medium-High
Hydra wrapped-asset depeg
Hydra locks native assets on core chains and mints OFT representations elsewhere; redemption depends on messaging, pool solvency, and the underlying asset remaining credible.
High
Medium
Global redemption design, native-asset backing, and route restrictions. Underlying stablecoin/issuer exposure remains external.
Medium-High
Governance and upgrade concentration
DAO-approved changes are typically implemented by the Stargate Foundation or LayerZero Labs, creating execution, capture, key-management, and rushed-upgrade risk.
High
Low
Forum discussion, Snapshot voting, quorum and approval thresholds, audits, and bounty coverage. Actual admin permissions are Not verifiable as of September 5, 2026.
Stargate V2’s top strengths are: (1) lower bridging costs via transaction batching/Bus mode and optimized contracts, which the docs and repo say materially reduce gas compared with V1; (2) capital efficiency through unified liquidity, credit allocation, and the AI Planning Module, which adapt liquidity to demand; (3) instant guaranteed finality, meaning source-chain transfers are settled immediately without rollback risk; (4) native-asset and omnichain reach, including Hydra, which extends core liquidity to additional chains and lets users receive redeemable native or OFT representations; and (5) broad composability and chain coverage, with support for multiple major networks and destination-chain contract interactions that make integration easier for DeFi use cases.