The crypto community spent several hours in a state of heightened alert due to reports of an alleged hack of wallets belonging to the LayerZero protocol. However, as a thorough investigation revealed, the movement of $2.4 million in funds was not an attack by malicious actors, but a standard internal liquidity management operation.

The first to raise the alarm was the security firm PeckShield, which detected suspicious transactions from the Executor wallets of the LayerZero protocol. According to their data, funds were withdrawn from several networks, including BNB Chain, Base, Arbitrum, Avalanche, Optimism, Mantle, Plasma, and Ethereum. The alleged attacker supposedly consolidated the stolen assets on the Ethereum network, exchanging most of them for 956 ETH (~$1.79 million) and $322,000 in USDC.

This version was picked up by other observers. For example, WuBlockchain, citing Specter, reported losses of about $2.1 million and the transfer of funds through the Stargate and Relay services. Analyst Zakaria Sharif also suggested the compromise of the Executor wallet, estimating the damage at approximately $2.1 million.

Quick Refutation

However, the situation was resolved swiftly. The first to refute the attack theory were the protocol's own developers. LayerZero stated that the funds were withdrawn from internal wallets as part of standard asset operations, emphasizing that "nothing is at risk." Project co-founder Bryan Pellegrino also expressed bewilderment at the resulting panic, noting that it was merely a "routine consolidation of assets."

Independent analysts quickly confirmed this information. Expert Crypto Patel pointed out that reports of a "$2.4 million hack" turned out to be a false alarm, and the transfers were part of routine internal rebalancing. The Verdict service, in turn, noted that this incident caused the market to panic for about four hours: "956 ETH moved, headlines appeared, and some protocols paused operations."

Expert Comment: This case is an excellent lesson for all market participants. It demonstrates how quickly misinterpreted data can trigger a wave of panic and even lead to the temporary suspension of some protocols. The key takeaway here is the critical importance of verifying any information before making loud claims. Asset movements on the network should always be checked rather than immediately labeled as a hack. This is especially relevant in the current cycle, when the market is in a state of heightened sensitivity to any news regarding security.